CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-8094

Critical · CVSS 9.8

Mozilla Firefox / Thunderbird WebRTC — Improper Control of Code Generation (CWE-94) in WebRTC component

CVSS
9.8
nvd
EPSS
0.45%
37th pct
KEV
No
Class
other
CWE-94

Description

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Search profile — drives PoC discovery

Symbols WebRTCRTCPeerConnectionmfsa2026-41mfsa2026-44bug2035939Firefox ESR 140.10.2Thunderbird 140.10.2
Keywords CVE-2026-8094Firefox WebRTC CWE-94mfsa2026-41mfsa2026-44Firefox ESR 140.10.2 exploitThunderbird 140.10.2 exploitWebRTC code injection Firefoxbugzilla 2035939 PoCRHSA-2026:19160RHSA-2026:20566
Versions: Firefox ESR < 140.10.2; Thunderbird < 140.10.2

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z