
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-92032 is a sandbox escape vulnerability caused by an invalid pointer in the Graphics component of Mozilla Firefox and Thunderbird. Discovered and reported internally by Mozilla, it was publicly disclosed on September 15, 2026, alongside a broad set of security fixes. Affected products include Firefox versions prior to 156, Firefox ESR versions prior to 140.16 and 153.3, and Thunderbird versions prior to 156, 140.16, and 153.3. The vulnerability carries a CVSS v3.1 base score of 9.6 (Critical) per Feedly's assessment, though Mozilla's own advisory rates its impact as moderate (Mozilla Advisory mfsa2026-92, Mozilla Advisory mfsa2026-90).
The vulnerability is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and stems from an invalid pointer condition within Firefox's and Thunderbird's Graphics component (Bug 2068437). An attacker can exploit this flaw by delivering a specially crafted web page or email attachment that triggers the invalid pointer dereference, allowing the browser's content process sandbox to be escaped. Exploitation requires user interaction — specifically, a victim must visit a malicious page or open a crafted attachment — but no authentication or special privileges are needed on the attacker's side. The underlying bug details are restricted in Mozilla's Bugzilla (Mozilla Advisory mfsa2026-92, Mozilla Advisory mfsa2026-93).
Successful exploitation allows an unauthenticated remote attacker to escape the browser sandbox and potentially execute arbitrary code with the privileges of the browser process on the victim's system. This results in high confidentiality, integrity, and availability impact — an attacker could access sensitive user data, modify files, or install malware. Both desktop browsing (Firefox) and email client (Thunderbird) attack surfaces are affected, broadening the potential victim pool (Mozilla Advisory mfsa2026-90, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.156%, indicating a low near-term probability of exploitation. NVD's supplemental data classifies the vulnerability as not automatable and not currently exploited, though the technical impact is rated as total.
Mozilla has released patches addressing this vulnerability in the following versions: Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. Users and administrators should update to these versions immediately. As a temporary workaround prior to patching, users should exercise caution when visiting untrusted websites or opening email attachments from unknown sources in Thunderbird (Mozilla Advisory mfsa2026-90, Mozilla Advisory mfsa2026-92, Mozilla Advisory mfsa2026-93).
The vulnerability was identified and reported internally by Mozilla, and was disclosed as part of a large batch of security advisories on September 15, 2026. Downstream Linux distributions including SUSE and openSUSE issued security update announcements, and vulnerability scanners from Qualys and Tenable (Nessus) added detection coverage shortly after disclosure. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard aggregation by security news and advisory platforms.
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.16.0esr-1~deb12u1
sid
thunderbird: 1:153.3.0esr-1
trixie
thunderbird: 1:140.16.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."