← Back to browse · API

CVE-2026-2768

Severity
CRITICAL
CVSS
10.0
EPSS
0.00366
Risk score
40.13
CISA KEV
No
PoC
No
Published
2026-02-24
Modified
2026-07-15
First seen
2026-08-06
Aliases
CNVD-2026-15385, EUVD-2026-8490, GHSA-76RW-RJ58-MPQC
Products
Mozilla Firefox <148, Mozilla Firefox ESR <115.33, Mozilla Firefox ESR <140.8, Mozilla Thunderbird <148, Mozilla Thunderbird <140.8
Sources
cnvd CNVD-2026-15385
euvd EUVD-2026-8490

Description

Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

References