CVE-2026-2796
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
- Affected products
- Firefox, Thunderbird
- Mozilla Firefox
- < 148.0
- Mozilla Thunderbird
- < 148.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.6% (48th percentile)
- Weakness
- CWE-843
- NVD status
- Modified
- Published
- 2026-02-24
CVE-2026-2796 at NVD
9 known exploits for CVE-2026-2796
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2026-2796-repro
CVE-2026-2796
CVE-2026-74939-escape-the-mac-n-cheese-box
CVE-2026-2796-escape-wasm-by-using-wasm
CVE-2026-2796-and-CVE-2026-2768-escape-the-wasm-box
Exploit for Type Confusion in Mozilla Firefox
Exploit for Protection Mechanism Failure in Mozilla Firefox
Exploit for Type Confusion in Mozilla Firefox
Exploit for Type Confusion in Mozilla Firefox