EXPOSURES › CVE-2022-26485
CVE-2022-26485
HIGH ⌖ ON CISA KEV · EXPLOITEDFirefox use-after-free flaw in XSLT processing allows remote code execution.
A use-after-free vulnerability in Firefox's XSLT parameter processing enables arbitrary code execution, posing a severe risk to systems relying on the browser for web-based operations. DIB organizations must ensure their browsers are patched immediately, as this flaw was actively exploited in the wild and could lead to data breaches or ransomware deployment if unpatched.
Shame score — A critical RCE flaw in a widely used browser was actively exploited in the wild, demonstrating severe negligence in patch management and leaving organizations exposed to remote compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.