CVE-2026-92020

High8.8Published on September 15, 2026

Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

CVSS score8.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-120

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database