DIRAS TAKE
Treat this as urgent: the flaw requires no privileges or user interaction (pre-auth), enabling remote attackers to escape the browser sandbox. If you cannot patch immediately, restrict exposure and monitor affected hosts closely.
What is CVE-2026-92066?
A remote attacker can bypass the Firefox sandbox and achieve code execution in the browser; this issue is tracked as CVE-2026-92066. The flaw is a sandbox-escape in the Profile Backup component that affects Firefox; vendor version details are not listed in the provided facts. Exploitation requires only network access and does not require privileges or user interaction, making remote attacks feasible against exposed Firefox installations.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-92066 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-92066
- Restrict network exposure of browsers and block untrusted sites via web filters.
- Monitor browser processes and endpoint telemetry for signs of sandbox escape or unexpected child processes.
- Apply Mozilla’s official guidance and install vendor updates as soon as they are released.
- Increase logging and alerting on endpoints running Firefox and prepare to deploy updates via your software distribution tools.
Frequently asked questions
Is CVE-2026-92066 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-92066?
The provided facts do not include a vendor-published list of affected Firefox versions.
Is there a patch for CVE-2026-92066?
No patch is listed in the provided facts; apply vendor updates when Mozilla releases them and follow their guidance.
Does CVE-2026-92066 require authentication?
No; the vulnerability can be triggered without privileges or user interaction, so it does not require authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-92066
- cve.org/CVERecord?id=CVE-2026-92066
- bugzilla.mozilla.org/show_bug.cgi?id=2058093
- mozilla.org/security/advisories/mfsa2026-90
- mozilla.org/security/advisories/mfsa2026-94
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026