CVE-2026-8090
Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2
CVSS
7.3
Alto
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 7 may 2026 · Última mod.: 28 jul 2026 · CWE-416 · CWE-825
0.3%EPSS · 30 días0.3%
2026-08-142026-09-11
Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2034352
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-40/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-41/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-42/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-43/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-44/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19160
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20566
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20574
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21381
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22325
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22643
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24508
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24509
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24510
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24511
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24516
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24755
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24983
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25015
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-703418.5 ALT—
——0Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.5hCVE-2026-578427.0 ALT—
——0NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing the kernel to access a freed iovec buffer and subsequently free the same allocation a second time.1dCVE-2026-781337.5 ALT35.1%
——11libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.1dCVE-2026-781235.9 MED34.7%
——10strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.1dCVE-2026-457525.9 MED41.8%
——13Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when certain detection transforms are chained, the decompress transform pipeline could read from an inspection buffer after it had been reallocated and freed. The issue is reached during network traffic processing, but requires a malicious rule as Suricata will crash whatever the traffic. Version 8.0.5 contains a fix. As a workaround, avoid rules that chain `gunzip` or `zlib_deflate` with `max-size` bigger than 4096 after another transform.1dCVE-2026-457515.9 MED41.8%
——13Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could leave an inspection pointer referencing freed memory after a chained transform caused the backing buffer to be reallocated. The issue is reached during a specific network traffic processing, and requires a specific but not malicious rule. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, avoid rules that chain `dotprefix` transform after another one.1d