PT-2026-38432 · Mozilla+1 · Firefox Esr+1

·

CVE-2026-8094

·

Published

2026-05-07

·

Updated

2026-06-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 140.10.2
Description An issue exists within the WebRTC (Web Real-Time Communication) component, which allows for real-time communication between browsers without the need for plugins.
Recommendations Update to Firefox ESR version 140.10.2.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19160
ALSA-2026:20566
ALSA-2026:20574
BDU:2026-09769
CVE-2026-8094
OESA-2026-2292
OESA-2026-2349
OESA-2026-2350
OESA-2026-2351
OESA-2026-2352
OPENSUSE-SU-2026:10720-1
OPENSUSE-SU-2026:10738-1
OPENSUSE-SU-2026:21168-1
RHSA-2026:19160
RHSA-2026:20566
RHSA-2026:20574
RHSA-2026:24508
RHSA-2026:24509
RHSA-2026:24510
RHSA-2026:24511
RHSA-2026:24516
RHSA-2026:24755
RHSA-2026:24983
RHSA-2026:25015

Affected Products

Firefox Esr
Red Os