CVE-2026-2760 is a critical sandbox escape vulnerability in the Graphics: WebRender component of Mozilla Firefox and Thunderbird, affecting versions prior to 148 and specific ESR versions. This flaw allows an unauthenticated attacker to achieve full compromise of confidentiality, integrity, and availability with low attack complexity over the network, as indicated by its CVSS score of 10.0. While no public exploit intelligence like Metasploit modules or ExploitDB entries are currently available, the vulnerability has garnered some community discussion and media coverage. There is no evidence of active exploitation, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.33.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 148.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 128.0, < 140.8.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 140.8.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* | ||
< 148.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.