CVE-2026-92038
Description
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
In plain language
AI Act nowThis is a critical flaw in firefox and Thunderbird that can let an internet attacker bypass built-in safety checks, so small businesses using either should update promptly.
Unauthenticated network-accessible mitigation bypass in the Remote Settings Client component (CWE-693) may allow remote evasion of security controls with high confidentiality and integrity impact.
What to do now
- Check the installed version of firefox and Thunderbird on all business devices.
- Update firefox ESR to 153.3 or later, or firefox to 156 or later.
- Update Thunderbird ESR to 153.3 or later, or Thunderbird to 156 or later.
- Confirm updates completed successfully and remove older installations where practical.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-92038 and every CVE in our database. Create a free account — no credit card required.
Create Free Account