CVE-2026-92038: Mitigation bypass in the Remote Settings Client component
Published Sep 15, 2026
·Updated
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected Software
9 affected componentsFixes available
Firefox=156, =153.3
Mozilla Firefox<156
156
Mozilla Firefox ESR<153.3
153.3
Mozilla Thunderbird<156
156
Mozilla Thunderbird<153.3
153.3
Mozilla Firefox<153.3.0
Mozilla Firefox>=154.0.0<156.0.0
Mozilla Thunderbird<153.3.0
Mozilla Thunderbird>=154.0<156.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 156 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.3 - Upgrade
Upgrade
Firefox / Firefox ESR / Thunderbirdto a version that resolves this vulnerability.Fixed in 156 - Upgrade
Upgrade
Firefox / Firefox ESR / Thunderbirdto a version that resolves this vulnerability.Fixed in 153.3
Event History
Sep 15, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
Description
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Sep 16, 2026
Updated
via Mozilla·12:00 AM
Affected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-92033
- CVE-2026-92005
- CVE-2026-92006
- CVE-2026-92007
- CVE-2026-92008
- CVE-2026-92009
- CVE-2026-92010
- CVE-2026-92011
- CVE-2026-92012
- CVE-2026-92013
- CVE-2026-92015
- CVE-2026-92034
- CVE-2026-92035
- CVE-2026-92016
- CVE-2026-92017
- CVE-2026-92018
- CVE-2026-92019
- CVE-2026-92020
- CVE-2026-92022
- CVE-2026-92023
- CVE-2026-92024
- CVE-2026-92025
- CVE-2026-92026
- CVE-2026-92036
- CVE-2026-92027
- CVE-2026-92028
- CVE-2026-92029
- CVE-2026-92037
- CVE-2026-92038
- CVE-2026-92039
- CVE-2026-92040
- CVE-2026-92041
- CVE-2026-92042
- CVE-2026-92043
- CVE-2026-92044
- CVE-2026-92045
- CVE-2026-92030
- CVE-2026-92046
- CVE-2026-92047
- CVE-2026-92048
- CVE-2026-92049
- CVE-2026-92050
- CVE-2026-92051
- CVE-2026-92052
- CVE-2026-92053
- CVE-2026-92054
- CVE-2026-92055
- CVE-2026-92056
- CVE-2026-92057
- CVE-2026-92031
- CVE-2026-92032
- CVE-2026-92058
- CVE-2026-92059
- CVE-2026-92060
- CVE-2026-92061
- CVE-2026-92062
- CVE-2026-92063
- CVE-2026-92064
- CVE-2026-92065
- CVE-2026-92066
- CVE-2026-92067
- CVE-2026-92068
- CVE-2026-92069
- CVE-2026-92070
- CVE-2026-92071
- CVE-2026-92072
- CVE-2026-92073
- CVE-2026-92074
- CVE-2026-92075
- CVE-2026-92076
- CVE-2026-92077
- CVE-2026-92078
- CVE-2026-92079
- CVE-2026-92238
- CVE-2026-92239
- CVE-2026-92240
Frequently Asked Questions
1
Which releases should be deployed to obtain the fix?
Deploy Firefox 156 or Firefox ESR 153.3, which include the fix for this issue.