CVE-2026-2757
Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox
CVSS
9.8
Critical
EPSS
0.5%
p41
KEV
—
Exploit Today
12
0-100
Published: Feb 24, 2026 · Last modified: Jul 15, 2026 · CWE-1384
0.5%EPSS · 30 days0.5%
2026-08-242026-09-22
Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2001637
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-13/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-14/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-15/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-16/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-17/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3338
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3339
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3361
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3491
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3492
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3493
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3494
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3495
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3496
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3497
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3515
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3516
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3517
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3976
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-493254.6 MED5.6%
——2Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation.63dCVE-2026-276010.0 CRI33.6%
——10Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.70dCVE-2026-27599.8 CRI33.6%
——10Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.70d