« All news

AlertCritical

Mozilla fixes a critical sandbox escape flaw in Firefox and Thunderbird

CVE-2026-100758, rated 9.6 on the CVSS scale, allows attackers to break out of the browser sandbox via the DOM: Navigation component. It affects Firefox, Firefox ESR and Thunderbird, and is already fixed in the releases Mozilla published on 29 September 2026.

What happened

Mozilla has released security advisory MFSA2026-100, which addresses a set of flaws in Firefox ESR 153.4. The most serious is CVE-2026-100758, a sandbox escape in the DOM: Navigation component, rated 9.6 (critical) by NVD.

The sandbox is the barrier that isolates web content from the rest of the operating system. A flaw of this kind lets a malicious page break that isolation and act outside the browser's controlled area. The CVSS vector shows the attack can be launched remotely, without prior credentials and with low complexity, although it requires user interaction (for example, clicking a link or visiting a crafted website). The potential impact covers confidentiality, integrity and availability of the machine.

Beyond this issue, Mozilla's advisory also covers a large number of additional memory-safety problems (use-after-free, uninitialised memory and further sandbox escapes) in components such as graphics, WebAssembly, XSLT and storage. Mozilla notes in the advisory that it now issues a separate entry for each individual bug instead of grouping them.

Who is affected

This affects users of Mozilla's browsers and email client on all platforms. According to the published information, fixes are available in:

Exploitation status

CVE-2026-100758 does not appear in CISA's KEV catalogue, so there is no confirmed active exploitation at this time. FIRST estimates a 0.2 % probability of exploitation within the next 30 days, a low figure compared with known vulnerabilities overall.

That low score should not reduce the urgency. This is a critical flaw in a component that processes content from the internet, exactly the kind of bug that tends to end up in exploit kits and in attack chains combined with other browser flaws. Mozilla has not reported any ongoing exploitation in its advisory.

What to do

The key action is to update. We recommend that IT teams:

Context

Public technical detail is limited: the original Bugzilla report (bug 2049792) remains restricted, a common Mozilla practice until most of the user base has updated. Advisory MFSA2026-100 is therefore the reference source for affected and fixed versions.

Sources

Affected technologies

Mozilla FirefoxMozilla Firefox ESRMozilla Thunderbird

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-100758Critical (9.6)—9/29/2026Undergoing Analysis

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.