← back
CVE-2020-26950

CVE-2020-26950

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 42%
from disclosure to weapon0 days
Published on NVDDec 9
metasploitNov 18
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.