2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100807 | HIGH | 8.8 | — | Sep 29, 2026 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 1... |
| CVE-2026-100806 | — | — | — | Sep 29, 2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15... |
| CVE-2026-100805 | — | — | — | Sep 29, 2026 | Race condition, use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100804 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100803 | — | — | — | Sep 29, 2026 | Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157... |
| CVE-2026-100802 | — | — | — | Sep 29, 2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100801 | HIGH | 8.8 | — | Sep 29, 2026 | Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and ... |
| CVE-2026-100800 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ES... |
| CVE-2026-100799 | — | — | — | Sep 29, 2026 | Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100798 | — | — | — | Sep 29, 2026 | Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 1... |
| CVE-2026-100797 | HIGH | 8.8 | — | Sep 29, 2026 | Privilege escalation due to use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox... |
| CVE-2026-100796 | — | — | — | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100795 | — | — | — | Sep 29, 2026 | Denial-of-service in the Networking component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100794 | — | — | — | Sep 29, 2026 | Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed ... |
| CVE-2026-100793 | — | — | — | Sep 29, 2026 | JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157. |
| CVE-2026-100792 | — | — | — | Sep 29, 2026 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ... |
| CVE-2026-100791 | — | — | — | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefo... |
| CVE-2026-100790 | — | — | — | Sep 29, 2026 | Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42... |
| CVE-2026-100789 | — | — | — | Sep 29, 2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Fire... |
| CVE-2026-100788 | — | — | — | Sep 29, 2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157... |
| CVE-2026-100787 | — | — | — | Sep 29, 2026 | Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. |
| CVE-2026-100786 | — | — | — | Sep 29, 2026 | Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firef... |
| CVE-2026-100785 | — | — | — | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefo... |
| CVE-2026-100784 | — | — | — | Sep 29, 2026 | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, ... |
| CVE-2026-100783 | — | — | — | Sep 29, 2026 | Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firef... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now