Review reviewCritical
CVE-2026-8948
Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
- CVSS
- 9.1
- EPSS
- 0.42% 34.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.19