CVE-2019-17026
ENISA EUVD: EUVD-2019-7500 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
2 articles
EPSS Score
Source: FIRST.org · 2026-05-24
55.55%
probability
This CVE has a 55.55% probability
of being exploited in the next 30 days.
0%
Top 98.1th percentile of all CVEs
100%
CVSS v3.1
Source: NVD8.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroType confusion in IonMonkey JIT compiler
Affected Products
Attack Intelligence
Google Project Zero
Discovered
Jan. 7, 2020
Patched
Jan. 8, 2020
Reported by
Qihoo 360 ATA
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2020/CVE-2019-17026.html
Exploits & PoC
lsw29475/CVE-2019-17026
PoC CVE-2019-17026 — lsw29475/CVE-2019-17026
3
1 repo — triés par ⭐
Rechercher sur GitHub ↗
Security Advisory 2020-001
CERT-EU
Jan 10, 2020
Mozilla Firefox 72.0.1 Patches Actively Exploited Zero-Day
BleepingComputer
Jan 08, 2020
Signal Intelligence
Confidence
92%
EPSS
55.55%
CVSS v3.1
8.8
Mentions
2
Last Seen
Jan 10, 2020
CNA Information
Analyst Note
CVE-2019-17026 is a confirmed high-severity type confusion vulnerability in Firefox's IonMonkey JIT compiler with documented active exploitation in the wild, corroborated by Google Project Zero inclusion and CERT-EU critical advisory coverage. The vulnerability affected multiple Mozilla products with specific patched versions identified (Firefox ESR 68.4.1+, Firefox 72.0.1+), providing strong evidence of real-world impact and remediation.
Triage Info
Decided atMar 03, 2026