← Back to browse · API

CVE-2026-2776

Severity
CRITICAL
CVSS
10.0
EPSS
0.00483
Risk score
40.17
CISA KEV
No
PoC
No
Published
2026-02-24
Modified
2026-07-15
First seen
2026-08-06
Aliases
CNVD-2026-20782, EUVD-2026-8498, GHSA-V33X-35CM-8GJC
Products
Mozilla Firefox <148, Mozilla Firefox ESR <115.33, Mozilla Firefox ESR <140.8, Mozilla Thunderbird <148, Mozilla Thunderbird <140.8
Sources
cnvd CNVD-2026-20782
euvd EUVD-2026-8498

Description

Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

References