CVE-2026-74956
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird
CVSS
9.1
Crítico
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 18 ago 2026 · Última mod.: 19 ago 2026 · CWE-843
Sin historial EPSS suficiente todavía.
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2032406
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-74/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-77/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-78/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-80/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-169199.8 CRÍ—
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.8hCVE-2026-760478.8 ALT32.1%
——10Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)19hCVE-2026-760388.8 ALT32.8%
——10Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)19hCVE-2026-528297.5 ALT36.1%
——11ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to plain IPv4 before storing it through MetaAddr::new_connected, but the mempool misbehavior path forwarded the raw transient address to MetaAddrChange::UpdateMisbehavior. In zebra-network/src/meta_addr.rs, apply_to_meta_addr then compared the canonical address-book entry with the raw update address and reached its unexpected address mismatch assertion. After the misbehavior batch flush, panic equals abort terminated zebrad; the peer only needed to complete a P2P handshake and advertise an invalid mempool transaction. This issue is fixed in version 4.5.0.2dCVE-2026-749766.5 MED6.0%
——2JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.1dCVE-2026-162398.8 ALT45.7%
——14Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.1d