PT-2026-77023 · Mozilla+1 · Firefox+2
CVE-2026-74990
·
Published
2026-08-18
·
Updated
2026-09-08
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox ESR version 115.38
Firefox ESR version 140.13
Firefox ESR version 153.0
Firefox version 153
Thunderbird ESR version 140.13
Thunderbird ESR version 153.0
Thunderbird version 153
Description
Internal bugs were identified that exhibit evidence of memory corruption or other security-relevant defects, which could potentially be exploited.
Recommendations
Update Firefox ESR 115.38 to version 115.39.
Update Firefox ESR 140.13 to version 140.14.
Update Firefox ESR 153.0 to version 153.1.
Update Firefox 153 to version 154.
Update Thunderbird ESR 140.13 to version 140.14.
Update Thunderbird ESR 153.0 to version 153.1.
Update Thunderbird 153 to version 154.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Rocky Linux
Thunderbird