VDB

CVE-2026-92032

CVE-2026-92032 PUBLISHED

Reported by mozilla · Published September 15, 2026

Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

EPSS 0.16% · 5.2th percentile

Risk Scores

EPSS Score
0.16%
5.2th percentile

Affected Products

VendorProductVersions
MozillaFirefox140.16, 153.3, 156
MozillaThunderbird140.16, 153.3, 156
MozillaFirefox156, 140.16, 153.3
MozillaThunderbird156, 140.16, 153.3

Timeline

  • Sep 15, 2026 Coalition ESS Score
  • Sep 15, 2026 CVE Published
  • Sep 16, 2026 EPSS Score
  • Sep 16, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›