s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-8959

📛 CVE Title

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Description

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Overview

State
PUBLISHED
Assigner (CNA)
mozilla
CVSS severity
critical
CVSS score
CVSS 9.6 / 10 9.6 9.6 / 10
CVSS vector
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Effective score
9.6 / 10 CRITICAL source: CNA overview
CWE(s)
Reserved
2026-05-19
Published
2026-05-19 12:29 UTC
Last updated
2026-05-19 17:10 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/8xxx/CVE-2026-8959.json
Linked Threat
CVE-2026-8959 — CVE-2026-8959

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-05-19 14:16:52 UTC
NVD last modified
2026-05-20 14:28:29 UTC
NVD CVSS v3.1
CVSS 9.6 / 10 9.6 9.6 / 10 CRITICAL source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability subscore
2.8 / 10
Impact subscore
6.0 / 10
EPSS score
0.0008 (probability of exploitation in next 30 days)
EPSS percentile
24.14% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD-assigned CWE(s): CWE-20, CWE-119, CWE-693 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-05-25 00:33 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-30910
Assigner
mozilla
Published
May 19, 2026, 12:29:55 PM
Updated
May 19, 2026, 5:10:50 PM
EUVD base score (CVSS 3.1)
9.6 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EUVD-reported EPSS
0.1600
Aliases
GHSA-3x92-cxc7-h2pw

ENISA description: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

EUVD references (5)

Affected products (2)

VendorProductVersionsPlatforms
Mozilla Firefox 140.11 (unaffected), 151 (unaffected)
Mozilla Thunderbird 140.11 (unaffected), 151 (unaffected)

Affected products — CPE 2.3 (4) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Vendor references (5)

References embedded in the original CVE record by the assigning CNA.

Web references (16)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (5)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (15)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:app.opencve.io

    A flaw in the Widget: Win32 component allows a malicious page to bypass the browser sandbox by exploiting incorrect boundary checks. This is an instance of buffer overrun and improper input validation (CWE-119) and insecure code path selection (CWE-693). The bug can lead to execution with higher privileges than the sandbox grants, potentially compromising the confidentiality, integrity, and ...

    2026-05-23 22:18 UTC
  • web:carthageelectronics.com

    Status: Actively exploited — CISA KEV listed — patch by May 12, 2026 What Happened On April 28, 2026 , CISA added CVE - 2026 -32202 to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation deadline of May 12, 2026 . This vulnerability is the result of an incomplete patch Microsoft released in February for CVE - 2026 -21510.

    2026-05-23 22:18 UTC
  • web:cvefeed.io

    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

    2026-05-23 22:18 UTC
  • web:cveinfo.com

    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde...

    2026-05-23 22:18 UTC
  • web:learn.microsoft.com

    The EM service checks the issuer, the Extended Key Usage, and the certificate chain. After successful validation, the EM service applies the mitigation . Each mitigation is a temporary, interim fix until you can apply the Security Update that fixes the vulnerability. The EM service isn't a replacement for Exchange SUs.

    2026-05-23 22:18 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-05-23 22:18 UTC
  • web:securityvulnerability.io

    Critical sandbox escape vulnerability affecting Mozilla Firefox. Learn more about CVE-2026-8959 and mitigate risks.

    2026-05-23 22:18 UTC
  • web:ubuntu.com

    Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.

    2026-05-23 22:18 UTC
  • web:www.thehackerwire.com

    CVE-2026-8959 is a Critical severity vulnerability (CVSS 9.6). Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox...

    2026-05-23 22:18 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-05-23 22:18 UTC
  • web:securitricks.com

    CVE CVE-2026-8959 - Score : 9.6 - Source : security@mozilla.org - Description : Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.

    2026-05-26 02:58 UTC
  • web:www.forbes.com

    Updated May 17: This article, originally published May 16, has been updated to include further details on the emergency mitigation process recommended after the CVE - 2026 -42897 Microsoft Exchange ...

    2026-05-26 02:58 UTC
  • web:www.mozilla.org

    Description Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

    2026-05-26 02:58 UTC
  • web:www.rapid7.com

    vulnerability MFSA2026-46 Firefox: Security Vulnerabilities fixed in Firefox 151 ( CVE-2026-8959 )

    2026-05-26 02:58 UTC
  • web:www.tenable.com

    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

    2026-05-26 02:58 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-8959.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 9.6,
              "baseSeverity": "CRITICAL",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "CHANGED",
              "userInteraction": "REQUIRED",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-8959",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-19T16:07:42.543024Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-119",
                "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                "lang": "en",
                "type": "CWE"
              }
            ]
          },
          {
            "descriptions": [
              {
                "cweId": "CWE-20",
                "description": "CWE-20 Improper Input Validation",
                "lang": "en",
                "type": "CWE"
              }
            ]
          },
          {
            "descriptions": [
              {
                "cweId": "CWE-693",
                "description": "CWE-693 Protection Mechanism Failure",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-19T16:08:39.887Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Firefox",
          "vendor": "Mozilla",
          "versions": [
            {
              "lessThanOrEqual": "140.*",
              "status": "unaffected",
              "version": "140.11",
              "versionType": "rpm"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "151",
              "versionType": "rpm"
            }
          ]
        },
        {
          "product": "Thunderbird",
          "vendor": "Mozilla",
          "versions": [
            {
              "lessThanOrEqual": "140.*",
              "status": "unaffected",
              "version": "140.11",
              "versionType": "rpm"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "151",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Ameen Basha M K"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11."
            }
          ],
          "value": "Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-19T17:10:50.516Z",
        "orgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe",
        "shortName": "mozilla"
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2034754"
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-46/"
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-48/"
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-50/"
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-51/"
        }
      ],
      "title": "Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe",
    "assignerShortName": "mozilla",
    "cveId": "CVE-2026-8959",
    "datePublished": "2026-05-19T12:29:55.560Z",
    "dateReserved": "2026-05-19T12:29:54.802Z",
    "dateUpdated": "2026-05-19T17:10:50.516Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}