CVE-2026-92051: null pointer dereference in Mozilla Firefox

A remote, unauthenticated attacker can trigger a null pointer dereference in Mozilla Firefox's Graphics component and cause serious integrity and availability impacts (CVE-2026-92051). Mozilla addressed the underlying bug in Firefox 156 and Thunderbird 156; the vendor notes the fix in those releases. Exploitation requires only network access and no user interaction or valid account, according to the vulnerability metrics provided.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00566
CWE
CWE-476
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: the flaw scores critical and Mozilla has not published a broadly available patch timeline in the provided facts, so restrict exposure of affected browsers and prepare to apply vendor fixes as soon as they are released.

What is CVE-2026-92051?

A remote, unauthenticated attacker can trigger a null pointer dereference in Mozilla Firefox's Graphics component and cause serious integrity and availability impacts (CVE-2026-92051). Mozilla addressed the underlying bug in Firefox 156 and Thunderbird 156; the vendor notes the fix in those releases. Exploitation requires only network access and no user interaction or valid account, according to the vulnerability metrics provided.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92051 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-92051

  1. Limit exposure by blocking or filtering untrusted content and sources that render complex graphics in Firefox on perimeter and enterprise-managed systems.
  2. Enforce browser isolation or use managed browsing policies to reduce rendering of untrusted pages in vulnerable Firefox instances.
  3. Monitor endpoint and network logs for crashes or abnormal browser behavior and collect crash reports for forensic review.
  4. Apply Mozilla's official update to fixed releases immediately when vendors publish the patch and follow their guidance.

Frequently asked questions

Is CVE-2026-92051 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which Firefox versions are affected by CVE-2026-92051?

Mozilla's advisory indicates the issue was fixed in Firefox 156 (and in Thunderbird 156); use that information to prioritize updates when fixes are distributed.

Is there a patch for CVE-2026-92051?

As of 2026-09-30 there is no patch status listed in the provided facts beyond the vendor noting fixes in Firefox 156; follow Mozilla announcements for the official update and distribution details.

Does CVE-2026-92051 require authentication?

No. The vulnerability metrics indicate no privileges and no user interaction are required, so exploitation can be attempted remotely without authenticating to the browser.

References