CVE-2026-92041: mitigation bypass in Mozilla Firefox

A remote attacker can bypass mitigations in Firefox's DOM networking component and impact the confidentiality and integrity of the browser and its data; this issue is tracked as CVE-2026-92041. The supplied facts do not list specific affected Firefox releases. The CVSS vector shows the issue can be exploited over the network without authentication or user interaction, so any exposed Firefox instance could be at risk until vendor guidance or a patch is applied.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00354
CWE
CWE-693
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: this is a high-impact, network-exploitable vulnerability (CVSS 9.1) and no patch is listed in the provided facts—reduce exposure and follow Mozilla guidance as soon as it is published.

What is CVE-2026-92041?

A remote attacker can bypass mitigations in Firefox's DOM networking component and impact the confidentiality and integrity of the browser and its data; this issue is tracked as CVE-2026-92041. The supplied facts do not list specific affected Firefox releases. The CVSS vector shows the issue can be exploited over the network without authentication or user interaction, so any exposed Firefox instance could be at risk until vendor guidance or a patch is applied.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92041 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-92041

  1. Follow Mozilla's official advisory and apply vendor updates as soon as they are released.
  2. Restrict network exposure of Firefox instances by limiting access to trusted networks and blocking unnecessary inbound connections.
  3. Monitor browser logging and network activity for unusual connections or potential data exfiltration.
  4. Use defense-in-depth: enforce network-level filtering, endpoint detection, and isolate high-risk browsing where feasible.

Frequently asked questions

Is CVE-2026-92041 being actively exploited?

There are no public reports of active exploitation as of 2026-09-30.

Which Firefox versions are affected by CVE-2026-92041?

The available facts do not list specific affected Firefox releases, so affected versions are not specified here.

Is there a patch for CVE-2026-92041?

According to the provided facts, no patch is listed as available.

Does CVE-2026-92041 require authentication?

No; the published CVSS vector indicates the issue does not require authentication or user interaction.

References