CVE-2026-74986EPSS p44.4%

CVE-2026-74986CVE-2026-74986

mozilla / firefox

Description

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Scoring

CVSS 9.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.56% probability of exploitation · percentile 44.4% · 2026-10-05T12:00:23Z
Last modified2026-08-25
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.