Description
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw exists in the graphics component of Firefox and Thunderbird. The flaw permits an attacker to corrupt memory after the original object has been freed, which could allow the execution of arbitrary code. This vulnerability undermines confidentiality, integrity, and availability of the affected system if successfully exploited.

Affected Systems

Mozilla publishes this vulnerability for Firefox versions before 156 and Firefox ESR before 153.3, as well as Thunderbird before 156 and Thunderbird ESR before 153.3. Users running any of these outdated releases are impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation. Although the use‑after‑free flaw permits arbitrary code execution, the exploit probability remains low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and would be triggered through crafted graphics data delivered via web pages or email attachments that are processed by the victim’s application.

Generated by OpenCVE AI on September 20, 2026 at 17:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 156 or newer, or to Firefox ESR 153.3 or newer.
  • Upgrade Thunderbird to version 156 or newer.
  • Keep the application updated automatically and monitor vendor advisories for further patches or mitigations.

Generated by OpenCVE AI on September 20, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-667

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-667

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Use-after-free in the Graphics component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-20T00:21:15.652Z

Reserved: 2026-09-15T12:34:19.276Z

Link: CVE-2026-92058

cve-icon Vulnrichment

Updated: 2026-09-20T00:21:03.027Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:00.207

Modified: 2026-10-05T18:59:39.547

Link: CVE-2026-92058

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:19Z

Links: CVE-2026-92058 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses