CVE-2026-2796Disclosure(mozilla / firefox)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 20 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 13 signals
  • Disclosure: 6 classified signals
  • General: 5 classified signals
  • Peaked 8d ago at 4 mentions (2026-03-08); latest day: 1
  • 20 total mentions across 12 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline20 mentions / 12d
01234Mentions · 2026-02-24: 2Mentions · 2026-03-01: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 4Mentions · 2026-03-09: 1Mentions · 2026-03-10: 3Mentions · 2026-03-11: 1Mentions · 2026-04-04: 1Mentions · 2026-05-02: 2Mentions · 2026-05-11: 1Mentions · 2026-08-21: 2Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-10: 3PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-05-02: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-08-21: 2Exploit Tool / Code · 2026-03-10: 2Exploit Tool / Code · 2026-05-02: 1Exploit Tool / Code · 2026-08-21: 2Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-08-21: 2Technical Details · 2026-02-24: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 3Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-11: 1Technical Details · 2026-08-21: 202-2403-0103-0603-0803-0903-1003-1104-0405-0205-1108-2108-25
Signal classification4 categories
Disclosure
630.0%
PoC
630.0%
General
525.0%
Exploit
315.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure2
2026-03-011
Disclosure1
2026-03-061
PoC1
2026-03-084
Disclosure2General1PoC1
2026-03-091
General1
2026-03-103
Exploit2PoC1
2026-03-111
General1
2026-04-041
PoC1
2026-05-022
General1PoC1
2026-05-111
Disclosure1
2026-08-212
Exploit1PoC1
2026-08-251
General1
Full discourse20 posts
  • Mr. OS@ksg93rd
    PoC

    Reverse engineering Claude's CVE-2026-2796 exploit https://red.anthropic.com/2026/exploit/

    Post summary

    The note signals that an exploit for CVE‑2026‑2796 has been reverse engineered and links to further details, but offers no additional technical context or evidence of in‑the‑wild activity.

    268341536034.1K
    3.2K followersView on X
  • stratan@5tratan
    PoC

    Introducing What The Claude: Browser Edition. A series where we pick apart browser bugs found/reported by Claude. First up: CVE-2026-2796, a SpiderMonkey Wasm import bug that leads to addrof/fakeobj/read-write. https://github.com/str8outtaheap/publications/tree/main/research/firefox/CVE-2026-2796-wasm-call-bind-import-confusion

    Post summary

    The post announces CVE-2026-2796 and shares a GitHub repository likely containing a proof‑of‑concept exploit demonstrating addrof/fakeobj/read‑write capabilities in SpiderMonkey’s WebAssembly processing.

    22601188211.4K
    554 followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-2796 Vendor: Mozilla Product: Firefox Description: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. Link: https://github.com/SneakyNachos/CVE-2026-2796-escape-wasm-by-using-wasm https://github.com/sneakynachos/cve-2026-2796-and-cve-2026-2768-escape-the-wasm-box #dbugs_vuln

    Post summary

    The post announces a PoC/exploit for CVE-2026-2796, linking to GitHub code and noting the vulnerability was patched in Firefox 148 and Thunderbird 148.

    08035133.5K
    3.6K followersView on X
  • Fabio@degrigis
    PoC

    So, @AnthropicAI used 350 Claude's rounds to create a full exploit chain for CVE-2026-2796 (which is really cool). http://red.anthropic.com/2026/exploit/ But, I think the cool part of the story is that to confirm that bug, you only need 13minutes and $11 to get some real evidence :D https://t.co/eQKdbW9ORo

    Post summary

    Anthropic AI demonstrated a full exploit chain for CVE‑2026‑2796, linking to the PoC and noting that confirming the bug takes only 13 minutes and $11.

    00053360
    609 followersView on X
  • Hermes Tool@Hermes_tooll
    Exploit

    Reverse engineering Claude's CVE-2026-2796 exploit https://red.anthropic.com/2026/exploit/

    Post summary

    The post signals that a functional exploit for CVE-2026-2796 is publicly available via a link, but provides no details about active attacks, patches, or vulnerability specifics.

    010511.7K
    2.5K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #reversing 1⃣ Getting a Shell on the Tapo C260 Camera (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) https://spaceraccoon.dev/getting-shell-tapo-c260-webcam // Reverse-engineered Tapo C260 firmware reveals vulnerabilities enabling local file disclosure and full RCE through path traversal and configuration manipulation 2⃣ nginx UI Vulnerability https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762 // CVE-2026-27944 (9.8/10) 3⃣ Patch diff to SYSTEM https://www.elastic.co/security-labs/patch-diff-to-system // Researchers utilized LLMs and patch diffing to develop a reliable privilege escalation exploit for Windows DWM via a UAF, demonstrating AI's growing role in vulnerability discovery and exploitation 4⃣ Reverse engineering Claude's CVE-2026-2796 exploit https://red.anthropic.com/2026/exploit ]-> Claude Code skill to support Android app's reverse engineering https://github.com/SimoneAvogadro/android-reverse-engineering-skill

    Post summary

    The post shares PoC and exploit details for several CVEs—including RCE on the Tapo C260 camera and a high‑severity nginx UI flaw—alongside AI‑assisted privilege escalation research.

    10024544
    3.2K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2025-55182 CVE-2026-2796 CVE-2026-2768 CVE-2026-34910 CVE-2026-34909 CVE-2026-58231 CVE-2026-48907 ..🧵👇

    Post summary

    The post lists several critical CVEs disclosed today but provides no additional details, PoC, or active exploitation information.

    11020167
    365 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Mozilla Firefox'un SpiderMonkey JavaScript motorunda bulunan (Thunderbird'de de kullanılan) WebAssembly güvenlik açığını (CVE-2026-2796) istismar eden bir PoC exploit yayınlandı. Zafiyet, Şubat 2026'da yayınlanan Firefox 148 ile yamalandı. https://github.com/SneakyNachos/CVE-2026-2796-escape-wasm-by-using-wasm

    Post summary

    A PoC exploit for CVE‑2026‑2796 targeting SpiderMonkey’s WebAssembly engine has been released, and the vulnerability was fixed in Firefox 148.

    00021476
    2.4K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-3094 2 - CVE-2025-43300 3 - CVE-2026-2796 4 - CVE-2026-1602 5 - CVE-2025-11411 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without providing technical details, exploitation status, or remediation information.

    00020223
    1.7K followersView on X
  • NoZart@NoZ4rt
    Disclosure

    @HipnoAmadeus @trianglerosmi @Munson_Royy @OfficialPCMR "more secure" #CVE-2026-2796: JIT miscompilation in the JavaScript WebAssembly, allowing attackers to use arbitrary read/write and code execution. Pwn2Own 2026: A demonstration exploited a 0-day using an out-of-bounds write in promise.allSettled, leading to remote code execution.

    Post summary

    The tweet announces CVE-2026-2796, a JavaScript WebAssembly JIT miscompilation that enables arbitrary read/write and RCE, and notes a Pwn2Own demonstration exploiting it.

    10000226
    35 followersView on X
  • ~lyn@lynettdoteth
    General

    @tiredhungryangr One? CVE-2026-2796, CVE-2026-24881, CVE-2026-24882, CVE-2025-32988, CVE-2025-32989, CVE-2025-64175, CVE-2026-25242, CVE-2026-28357, CVE-2026-28359, CVE-2026-26216, CVE-2026-26217, CVE-2026-25946, CVE-2026-32110, CVE-2026-30930, CVE-2026-30928, CVE-2026-32596...

    Post summary

    The message merely lists several CVE identifiers without providing any additional context, details, or actionable information.

    10000932
    825 followersView on X
  • Emre Doğan@emredogancloud
    Disclosure

    How it works: Claude explores the codebase → spots a bug → task verifier checks if an exploit runs → iterates. 112 unique reports submitted. CVE-2026-2796 (CVSS 9.8) — JIT miscompilation in Firefox's WebAssembly engine — came out of this loop. #Firefox

    Post summary

    A high‑severity JIT miscompilation bug (CVE‑2026‑2796) in Firefox’s WebAssembly engine was discovered through an automated bug‑finding loop; no exploit, patch, or active use is reported.

    1000037
    12 followersView on X
  • Cario Lee@QCL15
    PoC

    The worst one: CVE-2026-2796, scored CVSS 9.8/10. A JIT miscompilation bug in Firefox's JavaScript engine. Claude didn't just find it — it wrote a full exploit chain: use-after-free → type confusion → memory leak → arbitrary read/write → code execution A human researcher would typically need weeks to months for this.

    Post summary

    Researchers uncovered a critical JIT miscompilation flaw in Firefox (CVE‑2026‑2796) and already produced a full exploit chain, underscoring its severe code execution risk.

    1000082
    123 followersView on X
  • The Agent Economist@The_Agent_Econ
    General

    claude opus 4.6 found 22 firefox vulnerabilities in 14 days. 14 high-severity. then exploited one — CVE-2026-2796, a JIT miscompilation bug — in 20 minutes. no human pentester. just an LLM scanning a browser codebase. anthropic + mozilla partnership. all patched in firefox 148.

    Post summary

    An LLM (Claude Opus) scanned Firefox, found 22 high‑severity bugs, exploited one (CVE‑2026‑2796 – a JIT miscompilation bug) in 20 minutes, and Mozilla has patched all of them in Firefox 148.

    0000049
    6 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 𝐍𝐞𝐰 𝐯𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐚𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐩𝐮𝐛𝐥𝐢𝐬𝐡𝐞𝐝! AI-assisted vulnerability discovery unfolds as Anthropic's Claude Opus 4.6 uncovers CVE-2026-2796 in Firefox, illustrating AI's pivotal role in modern security research for defenders worldwide. 🔗 Get the complete details → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/cve-2026-2796-firefox-audit/ Join the discussion and tell us what you think!

    Post summary

    The post announces a new AI-discovered vulnerability, CVE-2026-2796 in Firefox, and directs readers to a detailed analysis link.

    0000052
    85 followersView on X
  • 다니엘멘탈리티@popo0290532790
    General

    근데 재밌는 건 22개 찾아놓고 실제 exploit 성공한 건 2건뿐이었다는 거.. 찾는 거랑 뚫는 건 아직 갭이 큼. 그래도 CVE-2026-2796 같은 경우 CVSS 9.8짜리 JIT 취약점인데 이걸 2주만에 찾았다는 게 솔직히 무섭긴 함. 기존 보안 업체들이 수혜 다 가져간다기보단 AI 보안 감사 전문 스타트업이 새로 치고 들어올 듯

    Post summary

    The text highlights that out of 22 discovered vulnerabilities, only 2 were successfully exploited and notes the rapid discovery of CVE-2026-2796, but provides no evidence of exploitation, patches, or PoC.

    0000047
    57 followersView on X
  • Dean@deantaplin
    PoC

    Anthropic’s "Reverse engineering Claude’s CVE-2026-2796 exploit" details how Claude Opus 4.6 independently identified and developed a POC exploit for a high-severity JIT miscompilation in Firefox's JavaScript engine, signaling a shift where AI can now perform end-to-end vulnerability research. https://red.anthropic.com/2026/exploit/

    Post summary

    Anthropic’s Claude generated a proof‑of‑concept exploit for a high‑severity Firefox JIT miscompilation, illustrating the growing capability of AI in end‑to‑end vulnerability research.

    00000119
    2.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2796 (CVSS:9.8, CRITICAL) is Modified. JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 and Thunderbird < ..https://nvd.nist.gov/vuln/detail/CVE-2026-2796 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2796, a critical JIT miscompilation flaw in Firefox and Thunderbird’s WebAssembly component, with CVSS 9.8, but provides no PoC, exploit, or patch details.

    0000045
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2796 JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148. https://www.cve.org/CVERecord?id=CVE-2026-2796 ----- Traducción: CVE-2026-2796 JIT malcompilación en el componente JavaScript: WebAssembly. Esta vulne… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-2796, a JIT miscompilation vulnerability in Firefox’s WebAssembly component affecting versions below 148.

    0000053
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2796 JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148. https://www.cve.org/CVERecord?id=CVE-2026-2796

    Post summary

    A JIT miscompilation vulnerability (CVE-2026-2796) affecting Firefox versions below 148 is disclosed, with a brief description of the affected component.

    000001.3K
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillathunderbird---

Explore more