CVE-2026-84131CWE-763

CVE-2026-84131

High · published September 1, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
25.6
In the wild
Unconfirmed
What it is

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00328 · 25.6th percentile
Weakness
CWE-763 · Release of Invalid Pointer or Reference
Published
2026-09-01T17:20Z
Affected products (7)
ProductVersionsFixed in
mozilla/firefox< 115.40.0115.40.0
mozilla/firefox≥ 116.0, < 140.15.0140.15.0
mozilla/firefox≥ 141.0.0, < 153.2.0153.2.0
mozilla/firefox≥ 154.0.0, < 155.0.0155.0.0
mozilla/thunderbird< 140.15.0140.15.0
mozilla/thunderbird≥ 141.0, < 153.2.0153.2.0
mozilla/thunderbird≥ 154.0, < 155.0155.0
References (8)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 12:18Z
    Privilege escalation due to invalid pointer in the Graphics component
    cvelistv5