Description
Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Potential Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free bug located in the Networking: Cache component of Mozilla Firefox. An attacker could potentially cause the browser to read or write memory after the associated object has already been freed, leading to memory corruption. Depending on the context, this flaw could be leveraged to execute arbitrary code or otherwise compromise the integrity and confidentiality of the victim system.

Affected Systems

This issue affects all Mozilla Firefox releases prior to the following security releases: Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Users running earlier versions of these browsers on any supported operating system are potentially vulnerable.

Risk and Exploitability

No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog, but use‑after‑free flaws are known to have a high exploitation likelihood when a suitable trigger can be induced. In the absence of a published exploit, the risk is considered significant because the flaw resides in a core networking component and could allow remote attackers to exploit the bug by serving malicious content. The CVSS score is not provided, but the nature of the bug suggests a high severity potential.

Generated by OpenCVE AI on September 29, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, or Firefox ESR 140.17, whichever corresponds to your current release stream.
  • Enable automatic updates for Firefox to receive any future security patches promptly.
  • If an update is not immediately available, consider temporarily disabling or limiting usage of browser caching for sensitive connections until the vulnerability is patched.

Generated by OpenCVE AI on September 29, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Use-after-free in the Networking: Cache component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T14:41:07.097Z

Reserved: 2026-09-26T19:15:23.891Z

Link: CVE-2026-100767

cve-icon Vulnrichment

Updated: 2026-09-29T14:40:44.319Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.940

Modified: 2026-09-29T15:17:12.640

Link: CVE-2026-100767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:30:17Z

Weaknesses