CVE-2026-92037: pre-auth remote code execution in Mozilla Firefox

Attackers can achieve remote code execution against Firefox by supplying specially crafted web content that triggers incorrect boundary handling in the DOM animation component; see CVE-2026-92037. The weakness is a memory-safety error (CWE-119) in the browser's DOM animation code. The vulnerability can be triggered remotely over the network and does not require a user to authenticate or interact with the page, allowing code execution in the context of the affected Firefox process.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00587
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a high-risk remote code execution bug because it can be triggered remotely with no authentication or user interaction, enabling full compromise of the browser process if exploited.

What is CVE-2026-92037?

Attackers can achieve remote code execution against Firefox by supplying specially crafted web content that triggers incorrect boundary handling in the DOM animation component; see CVE-2026-92037. The weakness is a memory-safety error (CWE-119) in the browser's DOM animation code. The vulnerability can be triggered remotely over the network and does not require a user to authenticate or interact with the page, allowing code execution in the context of the affected Firefox process.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92037 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-92037

  1. Restrict exposure by blocking or filtering untrusted web content and scripts at perimeter and endpoint controls.
  2. Enable and enforce automatic updates for Firefox and monitor vendor advisories for a formal patch.
  3. Monitor endpoints for anomalous child processes, crashes, or unexpected network connections from Firefox.
  4. Apply the vendor's guidance when a patch or mitigation is published and deploy it promptly.

Frequently asked questions

Is CVE-2026-92037 being actively exploited?

There are no public reports of exploitation of CVE-2026-92037 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-92037?

The facts provided do not specify an affected version range for Firefox; consult Mozilla advisories for an official list of affected and fixed releases.

Is there a patch for CVE-2026-92037?

A patch is not listed in the provided facts as of 2026-09-29; follow Mozilla security advisories for the availability of fixes.

Does CVE-2026-92037 require authentication?

No; the vulnerability can be triggered without authentication or user interaction against the Firefox process.

References