Mozilla fixes a critical sandbox escape flaw in Firefox and Thunderbird
CVE-2026-100758, rated 9.6 on the CVSS scale, allows attackers to break out of the browser sandbox via the DOM: Navigation component. It affects Firefox, Firefox ESR and Thunderbird, and is already fixed in the releases Mozilla published on 29 September 2026.
What happened
Mozilla has released security advisory MFSA2026-100, which addresses a set of flaws in Firefox ESR 153.4. The most serious is CVE-2026-100758, a sandbox escape in the DOM: Navigation component, rated 9.6 (critical) by NVD.
The sandbox is the barrier that isolates web content from the rest of the operating system. A flaw of this kind lets a malicious page break that isolation and act outside the browser's controlled area. The CVSS vector shows the attack can be launched remotely, without prior credentials and with low complexity, although it requires user interaction (for example, clicking a link or visiting a crafted website). The potential impact covers confidentiality, integrity and availability of the machine.
Beyond this issue, Mozilla's advisory also covers a large number of additional memory-safety problems (use-after-free, uninitialised memory and further sandbox escapes) in components such as graphics, WebAssembly, XSLT and storage. Mozilla notes in the advisory that it now issues a separate entry for each individual bug instead of grouping them.
Who is affected
This affects users of Mozilla's browsers and email client on all platforms. According to the published information, fixes are available in:
- Firefox 157 and Firefox ESR 153.4, 140.17 and 115.42
- Thunderbird 157, 153.4 and 140.17
Exploitation status
CVE-2026-100758 does not appear in CISA's KEV catalogue, so there is no confirmed active exploitation at this time. FIRST estimates a 0.2 % probability of exploitation within the next 30 days, a low figure compared with known vulnerabilities overall.
That low score should not reduce the urgency. This is a critical flaw in a component that processes content from the internet, exactly the kind of bug that tends to end up in exploit kits and in attack chains combined with other browser flaws. Mozilla has not reported any ongoing exploitation in its advisory.
What to do
The key action is to update. We recommend that IT teams:
- Update Firefox to version 157, and extended-support installations to Firefox ESR 153.4, 140.17 or 115.42, depending on the branch in use.
- Update Thunderbird to version 157, 153.4 or 140.17.
- Verify that automatic updates are enabled on managed endpoints and push the rollout where central policies apply.
- Prioritise workstations that browse the internet without filtering, executive devices and systems with access to sensitive data.
- Inventory installed versions after the rollout to confirm no endpoints remain on older builds.
Context
Public technical detail is limited: the original Bugzilla report (bug 2049792) remains restricted, a common Mozilla practice until most of the user base has updated. Advisory MFSA2026-100 is therefore the reference source for affected and fixed versions.
Sources
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2026-100758 | Critical (9.6) | — | 9/29/2026 | Undergoing Analysis |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.