T
Threats
Mozilla Firefox Multiple Critical Vulnerabilities
Overview
CVEs: CVE-2026-100762, CVE-2026-100770, CVE-2026-100778, CVE-2026-100786, CVE-2026-100800, CVE-2026-100804, CVE-2026-100811, CVE-2026-100818, CVE-2026-100819
Severity: Critical
Date: October 1 2026
Mozilla has published fixes for nine vulnerabilities affecting Firefox and Firefox ESR, including multiple use-after-free flaws and an incorrect boundary condition that could enable sandbox escapes.
Mozilla rates four vulnerabilities as High and five as Moderate, while the supplied project data assigns each a CVSS score of 9.6. Organisations should update to the applicable fixed Firefox or Firefox ESR release.
Vulnerability Breakdown
CVE-2026-100762 - Sandbox escape via use-after-free in DOM Content Processes
Severity: Critical, CVSS 9.6. Mozilla impact: High.
Description: Mozilla describes a use-after-free in the DOM Content Processes component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.
CVE-2026-100770 - Sandbox escape via use-after-free in DOM Content Processes
Severity: Critical, CVSS 9.6. Mozilla impact: High.
Description: Mozilla describes a use-after-free in the DOM Content Processes component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.
CVE-2026-100778 - Sandbox escape via use-after-free in DOM Core & HTML
Severity: Critical, CVSS 9.6. Mozilla impact: High.
Description: Mozilla describes a use-after-free in the DOM Core & HTML component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.
CVE-2026-100786 - Sandbox escape via use-after-free in Graphics
Severity: Critical, CVSS 9.6. Mozilla impact: High.
Description: Mozilla describes a use-after-free in the Graphics component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.
CVE-2026-100800 - Sandbox escape via use-after-free in Disability Access APIs
Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.
Description: Mozilla describes a use-after-free in the Disability Access APIs component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157 and Firefox ESR 153.4. Not affected: Not specified.
CVE-2026-100804 - Sandbox escape via use-after-free in Preferences Backend
Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.
Description: Mozilla describes a use-after-free in the Preferences Backend component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157. Not affected: Not specified.
CVE-2026-100811 - Sandbox escape via use-after-free in DOM Core & HTML
Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.
Description: Mozilla describes a use-after-free in the DOM Core & HTML component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, and Firefox ESR 140.17. Not affected: Not specified.
CVE-2026-100818 - Sandbox escape via use-after-free in Widget GTK
Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.
Description: Mozilla describes a use-after-free in the Widget GTK component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, and Firefox ESR 140.17. Not affected: Not specified.
CVE-2026-100819 - Sandbox escape via incorrect boundary conditions in XPCOM
Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.
Description: Mozilla describes incorrect boundary conditions in the XPCOM component.
Impact: Sandbox escape.
Conditions: Not specified in the accessible vendor advisory.
Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, and Firefox ESR 115.42. Not affected: Not specified.
Mitigation
Update Firefox and Firefox ESR installations to the applicable fixed release listed above.
Confirm the deployed browser channel and version against Mozilla's relevant security advisory before closing remediation.
The accessible advisories do not provide a workaround; prioritise the applicable vendor update.
Summary for IT Teams
Products: Mozilla Firefox and Firefox ESR
Threat Level: Critical, CVSS 9.6. Mozilla advisory impact ratings range from High to Moderate.
Action Required: Apply the applicable fixed Mozilla release. Confirm versions across managed endpoints.
Reference
Need Help?
Contact Secure ISS on 1300 769 460 or email the Secure ISS team for assistance assessing exposure and remediation.

