OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-92018 (CVSS 9.6)

NVD · officialPublished Sep 15, 2026Risk 50/100EPSS 0.4%

Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

CVSS
9.6
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source