CVE-2026-2786 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: February 25, 2026
Firefox - Use After Free
Overview
Firefox < 148 and Firefox ESR < 140.8 contain a use-after-free vulnerability in the JavaScript Engine component, letting attackers cause memory corruption or remote code execution, exploit requires crafted JavaScript execution.
Severity & Score
Impact
Attackers can cause memory corruption or execute arbitrary code remotely via crafted JavaScript.
Mitigation
Update to Firefox 148, Firefox ESR 140.8 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-2786 - Critical (9.8) Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8. š https://www.thehackerwire.com/vulnerability/CVE-2026-2786/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-2786
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- use_after_free
- Status
- confirmed
- EPSS
- 4.1%
- Social Posts
- 1
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H