Description
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Mitigation bypass
Action: Patch immediately
AI Analysis

Impact

This vulnerability involves the Widget: Win32 component in Mozilla Firefox and Thunderbird. It allows an attacker to bypass the default security mitigations that this component provides. Such a bypass could enable malicious actions that would otherwise be suppressed by the component’s protection mechanisms.

Affected Systems

Mozilla Firefox versions older than 156, Firefox ESR 153.3, and Mozilla Thunderbird older than 156 were affected. The security fixes were delivered as part of the 156 releases for both Firefox and Thunderbird.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity. The EPSS score of less than 1% indicates a low probability of exploitation at the time. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Based on the description, the likely attack vector is a malicious payload processed by the Widget: Win32 component, although specific environmental or prerequisites are not detailed.

Generated by OpenCVE AI on September 22, 2026 at 18:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 156 or newer.
  • Upgrade Mozilla Thunderbird to version 156 or newer.
  • Ensure all subsequent security updates are installed promptly.

Generated by OpenCVE AI on September 22, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-807
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Mitigation bypass in the Widget: Win32 component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-22T16:08:19.578Z

Reserved: 2026-09-15T12:34:40.765Z

Link: CVE-2026-92079

cve-icon Vulnrichment

Updated: 2026-09-22T16:02:43.802Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:03.560

Modified: 2026-10-05T19:01:22.410

Link: CVE-2026-92079

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:41Z

Links: CVE-2026-92079 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')