CVE-2026-92079: mitigation bypass in Mozilla Firefox

An unauthenticated remote attacker can bypass mitigations in Firefox's Widget: Win32 component, enabling high-impact code or control over the browser (CVE-2026-92079). The vendor has not published an affected-version list in the provided facts; the vulnerability scoring indicates it is exploitable remotely without privileges or user interaction, and no patch is available as of 2026-09-30.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00282
CWE
CWE-693
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: the flaw requires no authentication and allows remote impact, so immediately restrict exposure of Firefox instances and follow vendor guidance until a patch is released.

What is CVE-2026-92079?

An unauthenticated remote attacker can bypass mitigations in Firefox's Widget: Win32 component, enabling high-impact code or control over the browser (CVE-2026-92079). The vendor has not published an affected-version list in the provided facts; the vulnerability scoring indicates it is exploitable remotely without privileges or user interaction, and no patch is available as of 2026-09-30.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-92079 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-92079

  1. Restrict network exposure of Firefox instances (block or limit access to untrusted networks).
  2. Apply any vendor-recommended configuration mitigations and hardening guidance from Mozilla.
  3. Enable and enforce automatic updates for Firefox so fixes land promptly when released.
  4. Monitor browser telemetry and logs for anomalous crashes, exploitation indicators, or unexpected process behavior.

Frequently asked questions

Is CVE-2026-92079 being actively exploited?

There are no public reports of active exploitation of CVE-2026-92079 as of 2026-09-30.

Which Firefox versions are affected by CVE-2026-92079?

The provided facts do not include a published list of affected Firefox versions.

Is there a patch for CVE-2026-92079?

No, there is no patch available for CVE-2026-92079 in the provided facts as of 2026-09-30.

Does CVE-2026-92079 require authentication?

No, the vulnerability does not require authentication; it is exploitable remotely without privileges or user interaction.

References