CVE-2026-0886
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
MEDIUM · CVSS 5.3
EPSS 0.0002
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules1
YARA rules0