CVE-2026-92034: pre-auth remote code execution in Mozilla Firefox

A remote attacker can execute code in affected builds of Firefox via a site isolation issue in the Graphics component (CVE-2026-92034). The vendor-supplied data here does not include a definitive list of affected releases; patch availability is currently listed as false. Exploitation requires only network access and no authentication or user interaction, according to the published CVSS vector.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00293
CWE
CWE-346
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: the vulnerability has a CVSS 9.1 critical rating and no patch is listed, so isolate or block exposure of Firefox instances and apply vendor guidance as soon as a fix is released.

What is CVE-2026-92034?

A remote attacker can execute code in affected builds of Firefox via a site isolation issue in the Graphics component (CVE-2026-92034). The vendor-supplied data here does not include a definitive list of affected releases; patch availability is currently listed as false. Exploitation requires only network access and no authentication or user interaction, according to the published CVSS vector.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92034 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-92034

  1. Restrict network exposure of Firefox installations by blocking or limiting inbound access from untrusted networks.
  2. Monitor Firefox telemetry, logs, and intrusion detection alerts for suspicious graphics or renderer activity.
  3. Follow official Mozilla guidance and prepare to deploy updates immediately when Mozilla issues a patch.
  4. Apply standard mitigations such as disabling nonessential features and running browsers with least privilege.

Frequently asked questions

Is CVE-2026-92034 being actively exploited?

There are no public reports of active exploitation of CVE-2026-92034 as of 2026-09-30.

Which Firefox versions are affected by CVE-2026-92034?

The vendor-provided data in this record does not include a definitive list of affected Firefox releases.

Is there a patch for CVE-2026-92034?

A patch is not listed in the available data as of 2026-09-30; monitor Mozilla advisories for an official update.

Does CVE-2026-92034 require authentication?

No; the vulnerability requires no authentication or user interaction and can be triggered remotely over the network.

References