<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Firefox</title>
  <link>https://cvedaily.com/pages/tags/firefox.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/firefox.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Firefox</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-10702 – JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10702</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10702</strong></p>
  <p>JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10701 – Incorrect boundary conditions in the Graphics: Text component. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10701</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10701</strong></p>
  <p>Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9309 – Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9309</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9309</strong></p>
  <p>Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9308 – Firefox for iOS Reader View replaced page content in its HTML template before re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9308</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9308</strong></p>
  <p>Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9078 – Firefox for iOS displayed specially crafted right-to-left (RTL) and internationa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9078</guid>
    <pubDate>Mon, 25 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9078</strong></p>
  <p>Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8706 – Firefox for iOS hosted Reader mode on an unauthenticated local web server, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8706</guid>
    <pubDate>Tue, 19 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8706</strong></p>
  <p>Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8975 – Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8975</guid>
    <pubDate>Tue, 19 May 2026 14:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8975</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8974 – Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8974</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8974</strong></p>
  <p>Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8973 – Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8973</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8973</strong></p>
  <p>Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8972 – Privilege escalation in the WebRTC: Audio/Video component. This vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8972</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8972</strong></p>
  <p>Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8971 – Same-origin policy bypass in the Networking: JAR component. This vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8971</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8971</strong></p>
  <p>Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8970 – Privilege escalation in the Security component. This vulnerability was fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8970</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8970</strong></p>
  <p>Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8969 – Mitigation bypass in the DOM: Security component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8969</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8969</strong></p>
  <p>Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8968 – Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8968</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8968</strong></p>
  <p>Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8967 – Information disclosure in the Graphics: WebGPU component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8967</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8967</strong></p>
  <p>Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8966 – Information disclosure in the IP Protection component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8966</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8966</strong></p>
  <p>Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8965 – Information disclosure in the DOM: Security component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8965</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8965</strong></p>
  <p>Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8964 – Spoofing issue in the Popup Blocker component. This vulnerability was fixed in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8964</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8964</strong></p>
  <p>Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8963 – Spoofing issue in the Web Speech component. This vulnerability was fixed in Fire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8963</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8963</strong></p>
  <p>Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8962 – Mitigation bypass in the DOM: Security component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8962</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8962</strong></p>
  <p>Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8961 – Spoofing issue in the Form Autofill component. This vulnerability was fixed in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8961</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8961</strong></p>
  <p>Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8960 – Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8960</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8960</strong></p>
  <p>Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8959 – Sandbox escape due to incorrect boundary conditions in the Widget: Win32 compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8959</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8959</strong></p>
  <p>Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8958 – Information disclosure, sandbox escape in the Security: Process Sandboxing compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8958</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8958</strong></p>
  <p>Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8957 – Privilege escalation in the Enterprise Policies component. This vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8957</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8957</strong></p>
  <p>Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8956 – Integer overflow in the Networking: JAR component. This vulnerability was fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8956</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8956</strong></p>
  <p>Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8955 – Privilege escalation in the DOM: Workers component. This vulnerability was fixed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8955</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8955</strong></p>
  <p>Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8954 – Incorrect boundary conditions, integer overflow in the Audio/Video component. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8954</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8954</strong></p>
  <p>Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8953 – Sandbox escape due to use-after-free in the Disability Access APIs component. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8953</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8953</strong></p>
  <p>Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8952 – Privilege escalation in the Application Update component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8952</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8952</strong></p>
  <p>Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8951 – Spoofing issue in the Toolbar component in Firefox for Android. This vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8951</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8951</strong></p>
  <p>Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8950 – Same-origin policy bypass in the Networking: HTTP component. This vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8950</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8950</strong></p>
  <p>Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8949 – Integer overflow in the Widget: Win32 component. This vulnerability was fixed in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8949</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8949</strong></p>
  <p>Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8948 – Same-origin policy bypass in the DOM: Networking component. This vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8948</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8948</strong></p>
  <p>Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8947 – Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8947</guid>
    <pubDate>Tue, 19 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8947</strong></p>
  <p>Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8946 – Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8946</guid>
    <pubDate>Tue, 19 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8946</strong></p>
  <p>Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8945 – Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8945</guid>
    <pubDate>Tue, 19 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8945</strong></p>
  <p>Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42177 – linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42177</guid>
    <pubDate>Tue, 12 May 2026 18:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42177</strong></p>
  <p>linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a | or || anchor is substring-matched against the full request URL. The same applied rule action is mo…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8401 – Sandbox escape in the Profile Backup component. This vulnerability was fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8401</guid>
    <pubDate>Tue, 12 May 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8401</strong></p>
  <p>Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8391 – Other issue in the JavaScript Engine component. This vulnerability was fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8391</guid>
    <pubDate>Tue, 12 May 2026 14:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8391</strong></p>
  <p>Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8390 – Use-after-free in the JavaScript: WebAssembly component. This vulnerability was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8390</guid>
    <pubDate>Tue, 12 May 2026 14:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8390</strong></p>
  <p>Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8389 – JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8389</guid>
    <pubDate>Tue, 12 May 2026 14:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8389</strong></p>
  <p>JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8388 – Incorrect boundary conditions in the JavaScript Engine: JIT component. This vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8388</guid>
    <pubDate>Tue, 12 May 2026 14:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8388</strong></p>
  <p>Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44659 – Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44659</guid>
    <pubDate>Mon, 11 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44659</strong></p>
  <p>Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the actual registrable domain (eTLD+1). As a result, an attacker can craft extremely long malicious subdomains that visually imitate trusted brands, and the browser will display only the spoofed prefix, mi…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44658 – Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44658</guid>
    <pubDate>Mon, 11 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44658</strong></p>
  <p>Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same restriction. The provider maps each RSS/Atom item link into item.url, filters only for presence and date, and returns the item list. The live-folder manager later creates pinned lazy tabs from these va…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41431 – Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41431</guid>
    <pubDate>Mon, 11 May 2026 18:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41431</strong></p>
  <p>Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signatures, and the updater binary contains zero cryptographic verification code. This eliminates the defens…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8094 – Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8094</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8094</strong></p>
  <p>Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8093 – Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidenc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8093</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8093</strong></p>
  <p>Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8092 – Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Fir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8092</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8092</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8091 – Incorrect boundary conditions in the Audio/Video: Playback component. This vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8091</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8091</strong></p>
  <p>Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8090 – Use-after-free in the DOM: Networking component. This vulnerability was fixed in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8090</guid>
    <pubDate>Thu, 07 May 2026 13:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8090</strong></p>
  <p>Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7324 – Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7324</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7324</strong></p>
  <p>Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7323 – Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7323</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7323</strong></p>
  <p>Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7322 – Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7322</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7322</strong></p>
  <p>Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7321 – Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7321</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7321</strong></p>
  <p>Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7320 – Information disclosure due to incorrect boundary conditions in the Audio/Video c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7320</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7320</strong></p>
  <p>Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6786 – Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6786</guid>
    <pubDate>Sun, 26 Apr 2026 19:53:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6786</strong></p>
  <p>Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6785 – Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6785</guid>
    <pubDate>Sun, 26 Apr 2026 19:53:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6785</strong></p>
  <p>Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbir…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6784 – Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6784</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6784</strong></p>
  <p>Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6783 – Incorrect boundary conditions, integer overflow in the Audio/Video: Playback com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6783</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6783</strong></p>
  <p>Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6782 – Information disclosure in the IP Protection component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6782</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6782</strong></p>
  <p>Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6781 – Denial-of-service in the Audio/Video: Playback component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6781</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6781</strong></p>
  <p>Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6780 – Denial-of-service in the Audio/Video: Playback component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6780</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6780</strong></p>
  <p>Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6779 – Other issue in the JavaScript Engine component. This vulnerability was fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6779</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6779</strong></p>
  <p>Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6778 – Invalid pointer in the Audio/Video: Playback component. This vulnerability was f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6778</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6778</strong></p>
  <p>Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6777 – Other issue in the Networking: DNS component. This vulnerability was fixed in Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6777</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6777</strong></p>
  <p>Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6776 – Incorrect boundary conditions in the WebRTC: Networking component. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6776</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6776</strong></p>
  <p>Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6775 – Incorrect boundary conditions in the WebRTC component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6775</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6775</strong></p>
  <p>Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6774 – Mitigation bypass in the DOM: Security component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6774</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6774</strong></p>
  <p>Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6773 – Denial-of-service due to integer overflow in the Graphics: WebGPU component. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6773</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6773</strong></p>
  <p>Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6772 – Incorrect boundary conditions in the Libraries component in NSS. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6772</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6772</strong></p>
  <p>Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6771 – Mitigation bypass in the DOM: Security component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6771</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6771</strong></p>
  <p>Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6770 – Other issue in the Storage: IndexedDB component. This vulnerability was fixed in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6770</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6770</strong></p>
  <p>Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6769 – Privilege escalation in the Debugger component. This vulnerability was fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6769</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6769</strong></p>
  <p>Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6768 – Mitigation bypass in the Networking: Cookies component. This vulnerability was f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6768</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6768</strong></p>
  <p>Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6767 – Other issue in the Libraries component in NSS. This vulnerability was fixed in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6767</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6767</strong></p>
  <p>Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6766 – Incorrect boundary conditions in the Libraries component in NSS. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6766</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6766</strong></p>
  <p>Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6765 – Information disclosure in the Form Autofill component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6765</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6765</strong></p>
  <p>Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6764 – Incorrect boundary conditions in the DOM: Device Interfaces component. This vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6764</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6764</strong></p>
  <p>Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6763 – Mitigation bypass in the File Handling component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6763</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6763</strong></p>
  <p>Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6762 – Spoofing issue in the DOM: Core &amp; HTML component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6762</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6762</strong></p>
  <p>Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6761 – Privilege escalation in the Networking component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6761</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6761</strong></p>
  <p>Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6760 – Mitigation bypass in the Networking: Cookies component. This vulnerability was f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6760</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6760</strong></p>
  <p>Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6759 – Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6759</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6759</strong></p>
  <p>Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6758 – Use-after-free in the JavaScript: WebAssembly component. This vulnerability was ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6758</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6758</strong></p>
  <p>Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6757 – Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6757</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6757</strong></p>
  <p>Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6756 – Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6756</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6756</strong></p>
  <p>Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6755 – Mitigation bypass in the DOM: postMessage component. This vulnerability was fixe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6755</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6755</strong></p>
  <p>Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6754 – Use-after-free in the JavaScript Engine component. This vulnerability was fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6754</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6754</strong></p>
  <p>Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6753 – Incorrect boundary conditions in the WebRTC component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6753</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6753</strong></p>
  <p>Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6752 – Incorrect boundary conditions in the WebRTC component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6752</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6752</strong></p>
  <p>Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6751 – Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6751</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6751</strong></p>
  <p>Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6750 – Privilege escalation in the Graphics: WebRender component. This vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6750</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6750</strong></p>
  <p>Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6749 – Information disclosure due to uninitialized memory in the Graphics: Canvas2D com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6749</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6749</strong></p>
  <p>Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6748 – Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6748</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6748</strong></p>
  <p>Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6747 – Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6747</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6747</strong></p>
  <p>Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6746 – Use-after-free in the DOM: Core &amp; HTML component. This vulnerability was fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6746</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6746</strong></p>
  <p>Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5735 – Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5735</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5735</strong></p>
  <p>Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5734 – Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5734</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5734</strong></p>
  <p>Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5733 – Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5733</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5733</strong></p>
  <p>Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5733">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
