CVE-2026-92016: Use-after-free in the Disability Access APIs component
Published Sep 15, 2026
·Updated
Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, and Firefox ESR 153.3.
Affected Software
3 affected components
Mozilla Firefox<156
Mozilla Firefox ESR 140.16<140.16
Mozilla Firefox ESR 153.3<153.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 156 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.16 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 153.3
Event History
Sep 15, 2026
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
Description
Frequently Asked Questions
1
Which Firefox releases contain the fix?
The vulnerability was fixed in Firefox 156, Firefox ESR 140.16, and Firefox ESR 153.3.
2
Is there information on exploit prerequisites, affected default configurations, or temporary mitigations?
No exploit prerequisites, configuration conditions, detection guidance, or mitigations are provided in the available data.