CVE-2026-100778
CRITICAL
NVD
CVSS Score
9.6
Severity
CRITICAL
Published
Sep 29, 2026
Vendor
unknown
Description
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.