CVE-2026-74947
CVE-2026-74947 is a high-severity vulnerability in Mozilla Firefox with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-763.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- EPSS exploit prediction: 0% (16th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-763
- Affected product: Mozilla Firefox
- Published:
- Last modified:
Description
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Frequently asked questions
- What is CVE-2026-74947?
- Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- How severe is CVE-2026-74947?
- CVE-2026-74947 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-74947 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (16th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-74947?
- CVE-2026-74947 primarily affects Mozilla Firefox. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-74947?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-74947 published?
- CVE-2026-74947 was published on 2026-08-18 and last updated on 2026-08-21.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060010
- https://www.mozilla.org/security/advisories/mfsa2026-74/
- https://www.mozilla.org/security/advisories/mfsa2026-77/
- https://www.mozilla.org/security/advisories/mfsa2026-78/
- https://www.mozilla.org/security/advisories/mfsa2026-80/
Affected products (4)
- cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
- cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
More vulnerabilities in Mozilla Firefox
- CVE-2026-75874 — Critical (CVSS 10.0): Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
- CVE-2026-16367 — Critical (CVSS 10.0): Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox…
- CVE-2026-4725 — Critical (CVSS 10.0): Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149…
- CVE-2026-4692 — Critical (CVSS 10.0): Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR…
- CVE-2026-4689 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was…
- CVE-2026-4688 — Critical (CVSS 10.0): Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox…
All CVEs affecting Mozilla Firefox →
Other CWE-763 vulnerabilities
- CVE-2025-14233 — Critical (CVSS 9.8): Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may…
- CVE-2024-44852 — Critical (CVSS 9.8): Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation…
- CVE-2021-42377 — Critical (CVSS 9.8): An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution…
- CVE-2021-30473 — Critical (CVSS 9.8): aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
- CVE-2021-24028 — Critical (CVSS 9.8): An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code…
- CVE-2020-0103 — Critical (CVSS 9.8): In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This…