CVE-2026-74947EPSS p36.8%

CVE-2026-74947CVE-2026-74947

mozilla / firefox

Description

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Scoring

CVSS 8.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.45% probability of exploitation · percentile 36.8% · 2026-10-05T12:00:23Z
Last modified2026-08-21
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.