CVE-2026-0886: Incorrect boundary conditions in the Graphics component
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, and Firefox ESR < 140.7.
Other sources
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0886?
CVE-2026-0886 has been rated as a high severity vulnerability.
How do I fix CVE-2026-0886?
To fix CVE-2026-0886, update to Mozilla Firefox version 147 or Firefox ESR version 140.7 or 115.32.
What are the affected versions for CVE-2026-0886?
CVE-2026-0886 affects Firefox versions prior to 147, Firefox ESR versions prior to 115.32, and Firefox ESR versions prior to 140.7.
What is the nature of the vulnerability in CVE-2026-0886?
CVE-2026-0886 involves incorrect boundary conditions in the graphics component.
Which products should be prioritized for updates related to CVE-2026-0886?
Prioritize updates for Mozilla Firefox and Mozilla Firefox ESR products that are below the specified versions.