← Back to browse · API

CVE-2026-2778

Severity
CRITICAL
CVSS
10.0
EPSS
0.00483
Risk score
40.17
CISA KEV
No
PoC
No
Published
2026-02-24
Modified
2026-07-15
First seen
2026-08-06
Aliases
CNVD-2026-20775, EUVD-2026-8500, GHSA-3QGM-JCXP-M9M6
Products
Mozilla Firefox <148, Mozilla Firefox ESR <115.33, Mozilla Firefox ESR <140.8, Mozilla Thunderbird <148, Mozilla Thunderbird <140.8
Sources
cnvd CNVD-2026-20775
euvd EUVD-2026-8500

Description

Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

References