CVE-2026-92038: pre-auth mitigation bypass in Mozilla Firefox

An unauthenticated remote attacker can bypass security mitigations in Firefox's Remote Settings Client to achieve high-impact compromise (CVE-2026-92038). The flaw is a mitigation bypass (CWE-693) that allows remote, network-based attacks without user interaction or privileges. Specific affected Firefox and Thunderbird builds are not listed in the available data; an attacker only needs network access to the product to attempt exploitation.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00354
CWE
CWE-693
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is remotely exploitable without authentication, so reduce exposure immediately and prioritize vendor updates when available.

What is CVE-2026-92038?

An unauthenticated remote attacker can bypass security mitigations in Firefox's Remote Settings Client to achieve high-impact compromise (CVE-2026-92038). The flaw is a mitigation bypass (CWE-693) that allows remote, network-based attacks without user interaction or privileges. Specific affected Firefox and Thunderbird builds are not listed in the available data; an attacker only needs network access to the product to attempt exploitation.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92038 being exploited?

There are no public reports of exploitation as of 2026-09-30; the vulnerability is not listed in CISA's KEV catalog and no public exploit code is available.

How to fix CVE-2026-92038

  1. Restrict network exposure of Firefox installations and block unneeded inbound access to clients.
  2. Monitor logs and network traffic for suspicious Remote Settings Client activity and indicators of compromise.
  3. Follow Mozilla's official guidance and apply vendor updates as soon as a patch is released.
  4. Prepare to deploy updates quickly and test them in your environment before wide rollout.

Frequently asked questions

Is CVE-2026-92038 being actively exploited?

There are no public reports of exploitation as of 2026-09-30; it is not listed in CISA's Known Exploited Vulnerabilities catalog and no public exploit code is available.

Which Firefox versions are affected by CVE-2026-92038?

The available facts do not list specific affected Firefox or Thunderbird version numbers, only that the issue is in the Remote Settings Client component.

Is there a patch for CVE-2026-92038?

No patch is reported in the provided data; follow Mozilla's advisories and apply vendor updates when they are published.

Does CVE-2026-92038 require authentication?

No; the vulnerability is exploitable remotely without authentication or user interaction according to the reported impact.

References