CVE-2026-92061: pre-auth remote code execution in Mozilla Firefox

An unauthenticated remote attacker can achieve arbitrary code execution in Firefox by exploiting a buffer-bounds error in the browser's process sandboxing component. CVE-2026-92061 is a CWE-119 memory-bounds vulnerability that allows compromise without prior authentication or user interaction according to the published technical details and CVSS vector. The vendor has acknowledged the issue; specific affected and fixed release identifiers were not provided in the supplied facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00587
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a high-impact, no-authentication remote code execution bug (CVSS 9.8) — prioritize mitigation because the flaw lets attackers gain code execution without user interaction.

What is CVE-2026-92061?

An unauthenticated remote attacker can achieve arbitrary code execution in Firefox by exploiting a buffer-bounds error in the browser's process sandboxing component. CVE-2026-92061 is a CWE-119 memory-bounds vulnerability that allows compromise without prior authentication or user interaction according to the published technical details and CVSS vector. The vendor has acknowledged the issue; specific affected and fixed release identifiers were not provided in the supplied facts.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92061 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-92061

  1. Follow the vendor's security advisory and apply updates immediately when Mozilla releases fixes.
  2. Enable automatic updates for Firefox to ensure timely installation of any vendor patches.
  3. Restrict exposure: limit access to untrusted sites and consider enterprise policies that block or isolate high-risk web content.
  4. Monitor endpoints for signs of compromise and review browser telemetry and intrusion detection alerts for anomalous activity.

Frequently asked questions

Is CVE-2026-92061 being actively exploited?

There are no public reports of active exploitation or public exploit code for CVE-2026-92061 as of 2026-09-29.

Is there a patch for CVE-2026-92061?

A vendor fix was referenced in third-party reporting, but no patch details or fixed version identifiers are included in the supplied facts; apply vendor updates when Mozilla publishes them.

Does CVE-2026-92061 require authentication?

No — CVE-2026-92061 is exploitable without authentication or user interaction according to the provided technical data.

What can an attacker do with CVE-2026-92061?

An attacker can achieve arbitrary code execution in Firefox by exploiting the memory-bounds error in the process sandboxing component, enabling full compromise of the affected browser process.

References