← Back to browse · API

CVE-2026-2760

Severity
CRITICAL
CVSS
10.0
EPSS
0.00395
Risk score
40.14
CISA KEV
No
PoC
No
Published
2026-02-24
Modified
2026-07-15
First seen
2026-08-06
Aliases
CNVD-2026-20778, EUVD-2026-8482, GHSA-2255-92V8-4PVJ
Products
Mozilla Firefox <148, Mozilla Firefox ESR <115.33, Mozilla Firefox ESR <140.8, Mozilla Thunderbird <148, Mozilla Thunderbird <140.8
Sources
cnvd CNVD-2026-20778
euvd EUVD-2026-8482

Description

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

References