DIRAS TAKE
Treat this as high priority: there is no patch available in the provided facts while the issue enables bypass of enterprise policy controls, so restrict exposure and monitor until Mozilla publishes a fix.
What is CVE-2026-92057?
An attacker can bypass the Enterprise Policies component in Mozilla Firefox, undermining policy controls on affected installations; this is tracked as CVE-2026-92057. The available facts do not list specific affected Firefox versions or required attacker access, and no patch is available in the provided data. Administrators should assume enterprise policy controls could be circumvented until a vendor update is released.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-92057 being exploited?
There are no public reports of exploitation as of 2026-09-30; CISA has not added this CVE to the Known Exploited Vulnerabilities catalog and there is no public exploit code available in the provided facts.
How to fix CVE-2026-92057
- Limit exposure of managed Firefox installations to untrusted networks and users.
- Apply compensating controls for policy enforcement (network controls, endpoint restrictions, host-based enforcement).
- Monitor endpoint and network logs for suspicious changes to Firefox configuration or policy application failures.
- Watch Mozilla advisories and apply vendor-supplied updates as soon as a patch is released.
Frequently asked questions
Is CVE-2026-92057 being actively exploited?
As of 2026-09-30 there are no public reports of active exploitation; CISA has not listed this CVE in its Known Exploited Vulnerabilities catalog and no public exploit code is available in the provided facts.
Which Firefox versions are affected by CVE-2026-92057?
The provided facts do not include a list of affected Firefox versions; check Mozilla's official advisory for precise version information.
Is there a patch for CVE-2026-92057?
According to the provided facts, a patch is not available.
Does CVE-2026-92057 require authentication?
The available information does not state whether authentication is required for this vulnerability.
References
- nvd.nist.gov/vuln/detail/CVE-2026-92057
- cve.org/CVERecord?id=CVE-2026-92057
- bugzilla.mozilla.org/show_bug.cgi?id=2065646
- mozilla.org/security/advisories/mfsa2026-90
- mozilla.org/security/advisories/mfsa2026-93
- mozilla.org/security/advisories/mfsa2026-94
- mozilla.org/security/advisories/mfsa2026-96
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026