ZeroHour

CVE-2026-6754

CVSS 3.1
7.5 high
EPSS
<1%p32
Published
()
Modified
Description

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-416, CWE-825
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.