LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6785 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 26, 2026

Mozilla Firefox & Thunderbird - Remote Code Execution

Published: April 26, 2026Updated: April 26, 2026Remote Exploitable

Overview

Mozilla Firefox ESR 115.34, ESR 140.9, Thunderbird ESR 140.9, Firefox 149, and Thunderbird 149 contain memory safety bugs causing memory corruption, letting attackers potentially execute arbitrary code, exploit requires crafted input.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 5.5%(Probability of exploitation in next 30 days)

Impact

Attackers can exploit memory corruption to execute arbitrary code, potentially leading to full system compromise.

Mitigation

Update to Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, or Thunderbird 140.10.

References

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 26, 2026

🟠 CVE-2026-6785 - High (8.1) Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have be... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-6785/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 26, 2026

🟠 CVE-2026-6785 - High (8.1) Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have be... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-6785/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-6785
Severity
High
CVSS Score
8.1
Type
undefined
Status
new
EPSS
5.5%
Social Posts
2

CWE

  • CWE-125

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

5.5%Probability of exploitation in the next 30 days