← KEV catalog
CISA known exploited vulnerability

CVE-2022-26485

Mozilla Firefox Use-After-Free Vulnerability

SOURCE FACT

Mozilla · Firefox

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2022-26485

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?