PULSE
FEED
ransomshinyhunters reclama a WARNING · Not Foundransomm3rx reclama a intense.pl · PL · Technologyransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Foundransomshinyhunters reclama a WARNING · Not Foundransomm3rx reclama a intense.pl · PL · Technologyransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Found
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-100764

Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.

CVSS

8.8

High

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-119

EPSS · 30d

Not enough EPSS history yet.

Technical description

Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1008199.6 CRI
—
——0Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.10h
CVE-2026-1008148.8 HIG
—
——0Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.10h
CVE-2026-1007828.8 HIG
—
——0Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.10h
CVE-2026-1013549.6 CRI
29.8%
——9A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.13h
CVE-2026-1012056.3 MED
12.6%
——4A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds read. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.13h
CVE-2026-1012046.3 MED
12.6%
——4A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.13h