2026 CVE Vulnerabilities
45,701 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2790 | CRITICAL | 9.8 | 0.2% | Feb 24, 2026 | Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140... |
| CVE-2026-2789 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fir... |
| CVE-2026-2788 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ES... |
| CVE-2026-2787 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.3... |
| CVE-2026-2786 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thund... |
| CVE-2026-2785 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thun... |
| CVE-2026-2784 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunde... |
| CVE-2026-2782 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunde... |
| CVE-2026-2781 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thun... |
| CVE-2026-2780 | CRITICAL | 9.8 | 0.3% | Feb 24, 2026 | Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunde... |
| CVE-2026-2779 | CRITICAL | 9.8 | 0.6% | Feb 24, 2026 | Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR... |
| CVE-2026-2778 | CRITICAL | 10 | 0.5% | Feb 24, 2026 | Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in F... |
| CVE-2026-2777 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33,... |
| CVE-2026-2776 | CRITICAL | 10 | 0.5% | Feb 24, 2026 | Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability ... |
| CVE-2026-2775 | CRITICAL | 9.8 | 0.6% | Feb 24, 2026 | Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fi... |
| CVE-2026-2774 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ... |
| CVE-2026-2773 | CRITICAL | 9.8 | 0.6% | Feb 24, 2026 | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.3... |
| CVE-2026-2772 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, ... |
| CVE-2026-2771 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, F... |
| CVE-2026-2770 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33,... |
| CVE-2026-2768 | CRITICAL | 10 | 0.4% | Feb 24, 2026 | Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thun... |
| CVE-2026-2767 | CRITICAL | 9.8 | 0.4% | Feb 24, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8,... |
| CVE-2026-2766 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, ... |
| CVE-2026-2765 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thund... |
| CVE-2026-2764 | CRITICAL | 9.8 | 0.5% | Feb 24, 2026 | JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now