CVE-2026-92036: pre-auth remote code execution in Mozilla Firefox

A network attacker can trigger a memory-safety failure in Firefox's HTTP networking component and achieve remote code execution (CVE-2026-92036). The vulnerability is a CWE-119 boundary-condition bug in the Networking: HTTP code. The provided facts do not list a vendor-stated range of affected versions; third-party reporting indicates the issue was addressed in recent releases. An attacker requires only network access—no authentication or user interaction—to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00587
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: the flaw allows unauthenticated remote code execution over the network and the vendor has not published a patch in the provided facts.

What is CVE-2026-92036?

A network attacker can trigger a memory-safety failure in Firefox's HTTP networking component and achieve remote code execution (CVE-2026-92036). The vulnerability is a CWE-119 boundary-condition bug in the Networking: HTTP code. The provided facts do not list a vendor-stated range of affected versions; third-party reporting indicates the issue was addressed in recent releases. An attacker requires only network access—no authentication or user interaction—to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92036 being exploited?

There are no public reports of exploitation as of 2026-09-29 and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog; no public exploit code is available.

How to fix CVE-2026-92036

  1. Follow vendor security advisories and apply updates as soon as Mozilla publishes them.
  2. Reduce exposure by blocking or filtering untrusted HTTP traffic to Firefox endpoints where feasible.
  3. Monitor endpoint detection and response logs for anomalous crashes or suspicious activity from Firefox processes.
  4. Apply vendor-recommended mitigations for networking-related memory-safety issues until patches are available.

Frequently asked questions

Is CVE-2026-92036 being actively exploited?

There are no public reports of active exploitation of CVE-2026-92036 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-92036?

The provided facts do not include a vendor-published affected range; third-party reporting states the defect was fixed in Firefox 156 and Thunderbird 156.

Is there a patch for CVE-2026-92036?

No patch is listed in the provided facts as of 2026-09-29; watch Mozilla security advisories for an official update.

Does CVE-2026-92036 require authentication?

No; the vulnerability can be triggered without authentication or user interaction over the network.

References