CVE-2026-2779 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: February 25, 2026
Firefox - Buffer Overflow
Published: February 24, 2026Updated: February 25, 2026Remote Exploitable
Overview
Firefox < 148 and Firefox ESR < 140.8 contain a buffer overflow caused by incorrect boundary conditions in the Networking: JAR component, letting attackers potentially cause memory corruption, exploit requires crafted input.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can cause memory corruption, potentially leading to remote code execution or application crash.
Mitigation
Update to Firefox 148 or later and Firefox ESR 140.8 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-2779
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- buffer_overflow
- Status
- confirmed
CWE
- NVD-CWE-noinfo
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H