CVE-2026-92038

Critical9.1Published on September 15, 2026

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

CVSS score9.1 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness type (CWE)CWE-693

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database