s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-8945

📛 CVE Title

Sandbox escape in Firefox and Firefox Focus for Android

Description

Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

Overview

State
PUBLISHED
Assigner (CNA)
mozilla
CVSS severity
high
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
Reserved
2026-05-19
Published
2026-05-19 12:29 UTC
Last updated
2026-05-19 15:12 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/8xxx/CVE-2026-8945.json
Linked Threat
CVE-2026-8945 — CVE-2026-8945

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-05-19 14:16:50 UTC
NVD last modified
2026-05-21 20:56:23 UTC
NVD CVSS v3.1
CVSS 7.5 / 10 7.5 7.5 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability subscore
1.6 / 10
Impact subscore
5.9 / 10
EPSS score
0.0005 (probability of exploitation in next 30 days)
EPSS percentile
17.04% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD-assigned CWE(s): CWE-693 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-05-25 00:34 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-30897
Assigner
mozilla
Published
May 19, 2026, 12:29:34 PM
Updated
May 26, 2026, 5:47:40 PM
EUVD base score (CVSS 3.1)
7.5 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.0600
Aliases
GHSA-jvw5-v42q-rpwc

ENISA description: Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
Mozilla Firefox 151 (unaffected)

Affected products — CPE 2.3 (2) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
  • cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:android:*:*

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (9)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (16)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:app.opencve.io

    Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Upgrade to Firefox 151 or newer, which contains the fixed sandbox implementation. Upgrade Firefox Focus on Android to the latest release available through the Play Store.

    2026-05-23 22:18 UTC
  • web:community.broadcom.com

    A critical security issue, dubbed NGINX Rift and identified as CVE - 2026 -42945, has been disclosed. This vulnerability affects both NGINX Open Source and NGINX Plus. We are publishing this post to provide immediate guidance and confirm the rapid release of patched images for all affected Bitnami customers. Understanding the Critical Flaw: NGINX Rift ( CVE - 2026 -42945) The NGINX Rift vulnerability ...

    2026-05-23 22:18 UTC
  • web:guide.sonatype.com

    Technical security analysis for CVE-2026-8945 . CVSS 7.5 severity. View CVSS vectors, CWE classifications, and exploit maturity ratings.

    2026-05-23 22:18 UTC
  • web:hostcay.com

    A critical vulnerability in NGINX has moved from theoretical to operational threat within days of disclosure. CVE - 2026 -42945, a heap buffer overflow in the rewrite module, carries a CVSS score of 9.2 and is being actively weaponised in the wild. For operators running NGINX at scale—particularly those managing shared hosting, VPS platforms, or dedicated server infrastructure—this represents ...

    2026-05-23 22:18 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-05-23 22:18 UTC
  • web:orca.security

    A critical vulnerability ( CVE - 2026 -42945, CVSS 9.2) was disclosed affecting NGINX Open Source and NGINX Plus, allowing attackers to reliably trigger denial-of-service (DoS) conditions and potentially achieve remote code execution (RCE) via specially crafted HTTP requests. Due to the potential for widespread disruption across internet-facing applications and ingress infrastructure, immediate ...

    2026-05-23 22:18 UTC
  • web:socprime.com

    CVE - 2026 -42945 Mitigation The priority for CVE - 2026 -42945 mitigation is to upgrade to a fixed release. For NGINX Open Source, that means moving to 1.30.1 or 1.31.0. For NGINX Plus, the fixes were introduced in R32 P6 and R36 P4. Depthfirst also recommends restarting NGINX after the upgrade so worker processes reload the patched binary.

    2026-05-23 22:18 UTC
  • web:www.fosslinux.com

    I break down the critical NGINX Rift vulnerability ( CVE - 2026 -42945) affecting the rewrite module on Linux. Learn how to recursively audit your server configuration files for vulnerable rewrite patterns, implement immediate configuration mitigations using PCRE named capture groups, and successfully upgrade your active NGINX packages to the secure version 1.30.1 today.

    2026-05-23 22:18 UTC
  • web:www.imperva.com

    TL;DR: Researchers recently disclosed CVE - 2026 -42945, a critical heap-based buffer overflow vulnerability affecting both NGINX Open Source and NGINX Plus. The flaw exists within the ngx_http_rewrite_module component and can allow unauthenticated attackers to trigger denial-of-service conditions and potentially achieve remote code execution (RCE) using specially crafted HTTP requests. Imperva ...

    2026-05-23 22:18 UTC
  • web:www.thehackerwire.com

    CVE-2026-8945 is a High severity vulnerability (CVSS 7.5). Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

    2026-05-23 22:18 UTC
  • web:dailysecurityreview.com

    A critical heap buffer overflow hiding in NGINX's rewrite module for 18 years was publicly disclosed Wednesday, with security researcher "depthfirst" releasing full details of CVE - 2026 -42945 — a CVSS 9.2 flaw that allows unauthenticated remote code execution on servers running with ASLR disabled and reliable denial of service against any affected configuration. NGINX patched the ...

    2026-05-26 02:58 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-26 02:58 UTC
  • web:securitricks.com

    CVE CVE-2026-8945 - Score : 7.5 - Source : security@mozilla.org - Description : Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

    2026-05-26 02:58 UTC
  • web:securityboulevard.com

    Overview Recently, NSFOCUS CERT detected that Nginx and F5 issued security bulletins to fix the Nginx remote code execution vulnerability ( CVE - 2026 -42945); because the ngx_http_rewrite_module module contains question marks in processing (? ) has a defect in the calculation logic when replacing strings with rewrite. Under certain configuration conditions, an unauthenticated attacker can trigger ...

    2026-05-26 02:58 UTC
  • web:www.cisecurity.org

    Multiple vulnerabilities have been discovered in NGINX, the most severe of which could allow for remote code execution. NGINX is a software used for web serving, reverse proxying, caching, and load balancing. Successful exploitation of the most severe of these vulnerabilities may allow an unauthenticated threat actor to crash vulnerable NGINX worker processes by sending crafted HTTP requests ...

    2026-05-26 02:58 UTC
  • web:www.mozilla.org

    # CVE - 2026 -8969: Mitigation bypass in the DOM: Security component Reporter Atsushi Sada Impact low References Bug 2031123 # CVE - 2026 -8970: Privilege escalation in the Security component Reporter pakhunov.anton.n Impact low References Bug 2032174 # CVE - 2026 -8971: Same-origin policy bypass in the Networking: JAR component Reporter Surya Dev Singh ...

    2026-05-26 02:58 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-8945.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "HIGH",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 7.5,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "REQUIRED",
              "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-8945",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-19T15:11:15.996310Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-693",
                "description": "CWE-693 Protection Mechanism Failure",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-19T15:12:07.561Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Firefox",
          "vendor": "Mozilla",
          "versions": [
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "151",
              "versionType": "rpm"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Daisuke Hatakeyama"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151."
            }
          ],
          "value": "Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-19T12:29:34.775Z",
        "orgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe",
        "shortName": "mozilla"
      },
      "references": [
        {
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2003171"
        },
        {
          "url": "https://www.mozilla.org/security/advisories/mfsa2026-46/"
        }
      ],
      "title": "Sandbox escape in Firefox and Firefox Focus for Android"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f16b083a-5664-49f3-a51e-8d479e5ed7fe",
    "assignerShortName": "mozilla",
    "cveId": "CVE-2026-8945",
    "datePublished": "2026-05-19T12:29:34.775Z",
    "dateReserved": "2026-05-19T12:29:34.019Z",
    "dateUpdated": "2026-05-19T15:12:07.561Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}