LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6786 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 26, 2026

Mozilla Firefox & Thunderbird - Remote Code Execution

Published: April 26, 2026Updated: April 26, 2026Remote Exploitable

Overview

Mozilla Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149, and Thunderbird 149 contain memory safety bugs caused by memory corruption, letting attackers potentially execute arbitrary code, exploit requires successful memory corruption.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 4.6%(Probability of exploitation in next 30 days)

Impact

Attackers can exploit memory corruption to execute arbitrary code, potentially leading to full system compromise.

Mitigation

Update to Firefox 150, Firefox ESR 140.10, Thunderbird 150, or Thunderbird 140.10.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 26, 2026

🟠 CVE-2026-6786 - High (8.1) Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-6786/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 26, 2026

🟠 CVE-2026-6786 - High (8.1) Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-6786/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-6786
Severity
High
CVSS Score
8.1
Type
undefined
Status
new
EPSS
4.6%
Social Posts
2

CWE

  • CWE-125

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

4.6%Probability of exploitation in the next 30 days