CVE-2026-6777
published 2026-04-21CVE-2026-6777: Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.16%
5.7th percentile
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Firefox: Firefox: Unspecified security flaw in Networking: DNS component
vendor_redhat·2026-04-21·CVSS 5.3
CVE-2026-6777 [MEDIUM] CWE-676 Firefox: Firefox: Unspecified security flaw in Networking: DNS component
Firefox: Firefox: Unspecified security flaw in Networking: DNS component
A flaw was found in Firefox. This vulnerability affects the browser's Networking: DNS component. The specific nature of this issue and its potential impact are not detailed in the available information, but it represents an uncharacterized security concern.
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6777
vendor_mozilla·CVSS 5.3
CVE-2026-6777 [MEDIUM] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6777
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6777
Product: Firefox
Impact: high
Fixed in: Firefox 150
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6777
vendor_mozilla·CVSS 5.3
CVE-2026-6777 [MEDIUM] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6777
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6777
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
VulDB
Mozilla Firefox up to 149 DNS Remote Code Execution (Nessus ID 310629)
vuldb·2026-04-28·CVSS 5.3
CVE-2026-6777 [MEDIUM] Mozilla Firefox up to 149 DNS Remote Code Execution (Nessus ID 310629)
A vulnerability has been found in Mozilla Firefox up to 149 and classified as critical. Impacted is an unknown function of the component DNS. Performing a manipulation results in Remote Code Execution.
This vulnerability was named CVE-2026-6777. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-q3c8-p5vp-wr87: Other issue in the Networking: DNS component
ghsa_unreviewed·2026-04-21
CVE-2026-6777 [MEDIUM] CWE-20 GHSA-q3c8-p5vp-wr87: Other issue in the Networking: DNS component
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150.
No detection rules found.
No public exploits indexed.
2026-04-21
Published