---
cve: "CVE-2026-100763"
severity: "CRITICAL"
cvss: 9.1
epss: "0.2%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-09-29 13:17:40"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T03:14:26+02:00"
---

# CVE-2026-100763

> 9.1 CRITICAL

## Beschreibung

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

## CNA-Record (Kanon, cvelistV5)

- CNA: **mozilla**
- State: PUBLISHED
- Stand: 2026-10-01 14:37:02

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3654) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox ESR und Mozilla Firefox ausnutzen, um beliebigen Programmcode auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder andere, nicht näher spezifizierte Angriffe zu starten.

## Referenzen

- <https://bugzilla.mozilla.org/show_bug.cgi?id=2059929>
- <https://www.mozilla.org/security/advisories/mfsa2026-101/>
- <https://www.mozilla.org/security/advisories/mfsa2026-97/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-100763) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
