Description
Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
In plain language
AI Act nowFirefox and Thunderbird versions before their listed fixed releases can be compromised if someone opens malicious content, so small businesses should update them promptly.
CVE-2026-92029 is a high-severity use-after-free in the SVG component that can enable arbitrary code execution when a victim interacts with attacker-controlled content.
What to do now
- Check the version of Firefox and Thunderbird installed on every business computer.
- Update Firefox to 115.41, 140.16, 153.3, or 156, as appropriate for your release branch.
- Update Thunderbird to 140.16, 153.3, or 156, as appropriate for your release branch.
- Until updates are complete, tell staff not to open unexpected links or attachments, especially from unfamiliar senders.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-92029 and every CVE in our database. Create a free account — no credit card required.
Create Free Account