CVE-2026-8388
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
- Affected products
- Firefox, Rocky Linux
- Mozilla Firefox
- < 150.0.3
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-787, CWE-119
- NVD status
- Modified
- Published
- 2026-05-12
CVE-2026-8388 at NVD
1 known exploit for CVE-2026-8388
Proof-of-concept code and exploit modules indexed by Sploitus