Description
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Crash or DoS
Action: Patch
AI Analysis

Impact

The vulnerability is caused by incorrect boundary checks in the network component, which could lead to undefined behavior when processing malformed packets. This flaw is classified as CWE‑120 and may result in an application crash or denial of service. The description does not state that it allows arbitrary code execution; the impact is limited to instability or availability loss.

Affected Systems

Mozilla Firefox versions older than 156 (or older than ESR 153.3) and Mozilla Thunderbird versions older than 156 (or older than 153.3) are affected.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Since the flaw resides in the networking stack, an attacker would need to send crafted network traffic to the vulnerable application, which is the primary inferred attack vector.

Generated by OpenCVE AI on September 22, 2026 at 18:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Firefox or Thunderbird releases that incorporate the fix (Firefox 156, ESR 153.3, Thunderbird 156 or ESR 153.3).
  • If an upgrade is not immediately possible, limit inbound network traffic to the application or use host‑based filtering to restrict contact to trusted networks.
  • Apply general OS and kernel updates that address networking stack issues to reduce the risk of exploitation.

Generated by OpenCVE AI on September 22, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Incorrect boundary conditions in the Networking component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-22T16:08:25.160Z

Reserved: 2026-09-15T12:34:37.754Z

Link: CVE-2026-92076

cve-icon Vulnrichment

Updated: 2026-09-22T15:58:00.881Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:03.180

Modified: 2026-10-05T19:31:48.487

Link: CVE-2026-92076

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:38Z

Links: CVE-2026-92076 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')