PT-2026-33972 · Mozilla+1 · Firefox+2
Alex Franchuk
+7
·
Published
2026-04-21
·
Updated
2026-05-25
·
CVE-2026-6786
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox ESR version 140.9
Thunderbird ESR version 140.9
Firefox version 149
Thunderbird version 149
Description
Memory safety bugs involving memory corruption could allow an attacker to run arbitrary code.
Recommendations
Update Firefox ESR to version 140.10.
Update Thunderbird ESR to version 140.10.
Update Firefox to version 150.
Update Thunderbird to version 150.
Fix
DoS
Memory Corruption
Out of bounds Read
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Rocky Linux
Thunderbird