Kaspersky ID:
KLA90902
Detect Date:
02/24/2026
Updated:
02/25/2026

Description

Multiple vulnerabilities were found in Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, gain privileges, bypass security restrictions, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability can be exploited to cause denial of service or execute arbitrary code.
  2. An elevation of privilege vulnerability in Netmonitor can be exploited remotely to gain privileges.
  3. Memory safety vulnerability can be exploited to execute arbitrary code.
  4. Security vulnerability in Networking can be exploited to bypass security restrictions.
  5. Use after free vulnerability in JavaScript Engine can be exploited to cause denial of service or execute arbitrary code.
  6. Use after free vulnerability in DOM: Window and Location can be exploited to cause denial of service or execute arbitrary code.
  7. Use after free vulnerability in DOM: Bindings (WebIDL) and Location can be exploited to cause denial of service or execute arbitrary code.
  8. Heap buffer overflow vulnerability in JavaScript: Standard Library can be exploited to cause denial of service.
  9. Information disclosure vulnerability in JIT can be exploited to obtain sensitive information.
  10. Heap buffer overflow vulnerability can be exploited to cause denial of service.
  11. Security vulnerability can be exploited to bypass security restrictions.
  12. An elevation of privilege vulnerability can be exploited remotely to gain privileges.

Original advisories

Exploitation

Related products

CVE list

  • CVE-2026-2757
    unknown
  • CVE-2026-2758
    unknown
  • CVE-2026-2759
    unknown
  • CVE-2026-2760
    unknown
  • CVE-2026-2761
    unknown
  • CVE-2026-2762
    unknown
  • CVE-2026-2763
    unknown
  • CVE-2026-2764
    unknown
  • CVE-2026-2765
    unknown
  • CVE-2026-2766
    unknown
  • CVE-2026-2767
    unknown
  • CVE-2026-2768
    unknown
  • CVE-2026-2769
    critical
  • CVE-2026-2770
    unknown
  • CVE-2026-2771
    unknown
  • CVE-2026-2772
    unknown
  • CVE-2026-2773
    unknown
  • CVE-2026-2774
    unknown
  • CVE-2026-2775
    unknown
  • CVE-2026-2776
    unknown
  • CVE-2026-2777
    unknown
  • CVE-2026-2778
    unknown
  • CVE-2026-2779
    unknown
  • CVE-2026-2780
    unknown
  • CVE-2026-2781
    unknown
  • CVE-2026-2782
    unknown
  • CVE-2026-2783
    unknown
  • CVE-2026-2784
    unknown
  • CVE-2026-2785
    unknown
  • CVE-2026-2786
    unknown
  • CVE-2026-2787
    unknown
  • CVE-2026-2788
    unknown
  • CVE-2026-2789
    unknown
  • CVE-2026-2790
    unknown
  • CVE-2026-2791
    unknown
  • CVE-2026-2792
    unknown
  • CVE-2026-2793
    unknown

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Do you want to save your changes?
Your message has been sent successfully.