CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-100779

CVE-2026-100779. CVSS base score 8.8 (HIGH, Source advisory). EPSS 0.0034 (percentile 0.252), scored 2026-10-04.

Affected technology

firefox · before 157.0.0 (exclusive)
mozilla

firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · before 157.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-416
CCR priority
35.3 /100 (P4)
CVSS
8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.0034 · percentile 0.252 · 2026-10-04
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-100779.html