Published January 13, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
- MozillaFirefox
- cpe:2.3:a:mozilla:firefox
Sources
AlmaLinux Security Advisory
AlmaLinux 8 Severity HIGHHas FixAdded at: Feb 11, 2026
AlmaLinux 9 Severity HIGHHas FixAdded at: Jan 20, 2026
Debian Security Tracker
Debian 11, 12, 13, 14 Severity CRITICALHas FixAdded at: Jan 13, 2026
Echo
Echo Severity CRITICALHas FixAdded at: Jan 13, 2026
Homebrew
Homebrew Severity CRITICALHas FixAdded at: Jan 23, 2026
Nix
Nix Severity CRITICALHas FixAdded at: Jan 23, 2026
Red Hat Errata
Red Hat 6, 7 Severity MEDIUMNo FixAdded at: Jan 14, 2026
Red Hat 8 Severity MEDIUMHas FixAdded at: Jan 14, 2026
Red Hat 9 Severity MEDIUMHas FixAdded at: Jan 14, 2026
Red Hat 10 Severity MEDIUMHas FixAdded at: Jan 14, 2026
Rocky Linux Product Errata
Rocky 8 Severity HIGHHas FixAdded at: Jan 18, 2026
Rocky 9 Severity HIGHHas FixAdded at: Jan 18, 2026
Ubuntu Security Tracker
Ubuntu 22.04 Severity MEDIUMHas FixAdded at: Jan 15, 2026
VulnCheck NVD++
Linux Severity CRITICALHas FixAdded at: Jan 14, 2026
Windows Severity CRITICALHas FixAdded at: Jan 14, 2026
NVD
Linux Severity CRITICALHas FixAdded at: Jan 23, 2026
Windows Severity CRITICALHas FixAdded at: Jan 23, 2026