SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-92021

UNKNOWN · CVSS N/A EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the JavaScript Engine's JIT component affects both Firefox and Java, potentially allowing attackers to execute arbitrary code. Organizations using these products, particularly those on older versions, should prioritize patching to mitigate the risk of exploitation. The issue has been addressed in Firefox ESR version 140.16, so immediate updates are recommended.

CVE
CVE-2026-92021
Severity
UNKNOWN
CVSS
N/A
EPSS
0.15%
Firefox Java

Original NVD Description

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.