
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75874 is a sandbox escape vulnerability in the Remote Settings Client component of Mozilla Firefox and Thunderbird. Discovered and reported by researcher "crixer," it was publicly disclosed on August 18, 2026, as part of Mozilla Foundation Security Advisories MFSA2026-74 (Firefox) and MFSA2026-78 (Thunderbird). All versions of Firefox and Thunderbird prior to version 154 are affected. It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its network-accessible, unauthenticated, no-user-interaction attack profile with a changed scope (Mozilla Advisory, Mozilla Advisory).
The vulnerability is classified under CWE-693 (Protection Mechanism Failure), indicating that the Remote Settings Client component fails to properly enforce sandbox restrictions, allowing code executing within the browser sandbox to escape into the host environment. The attack vector is network-based, requires no authentication, no privileges, and no user interaction, making it automatable and highly dangerous. The specific flaw resides in how the Remote Settings Client processes data, though the full technical details remain restricted in the Mozilla bug tracker (Bug 2039972). The vulnerability maps to CAPEC patterns including CAPEC-237 (Escaping a Sandbox by Calling Code in Another Language) and CAPEC-480 (Escaping Virtualization) (Mozilla Advisory).
Successful exploitation allows an unauthenticated remote attacker to break out of the Firefox or Thunderbird sandbox and execute arbitrary code with the privileges of the browser process on the host system. The CVSS score reflects total technical impact — full confidentiality, integrity, and availability compromise — with a changed scope, meaning the impact extends beyond the browser sandbox to the underlying operating system. This could enable an attacker to access sensitive user data, install malware, establish persistence, or pivot to other systems on the network. For Thunderbird, Mozilla notes the flaw is not exploitable via email (since scripting is disabled when reading mail), but it is a risk in browser-like contexts (Mozilla Advisory, Mozilla Advisory).
As of the disclosure date (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction, significantly raising the risk of future weaponization. No threat actor attribution has been reported at this time.
Mozilla has released patches addressing this vulnerability in Firefox 154 and Thunderbird 154, both announced on August 18, 2026. Users and administrators should update to these versions immediately. No configuration-based workarounds have been published by Mozilla; upgrading to the patched release is the only recommended remediation. Enterprise administrators should prioritize deployment via their software management tooling and monitor Mozilla security advisories for any further updates (Mozilla Advisory, Mozilla Advisory).
The vulnerability received coverage from security monitoring organizations including AusCERT (ESB-2026.9671) and the Western Australian Government SOC (advisory 20260819001), both issuing alerts on August 19, 2026. Community discussion appeared on Reddit's r/pwnhub in a CVE daily brief. Kaspersky also catalogued the vulnerability (KLA91226). No notable independent researcher commentary or major media coverage beyond standard advisory aggregation has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."