CVE-2026-6779
published 2026-04-21CVE-2026-6779: Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.21%
11.1th percentile
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JavaScript Engine: Firefox: Firefox: Unspecified vulnerability in JavaScript Engine
vendor_redhat·2026-04-21·CVSS 5.3
CVE-2026-6779 [MEDIUM] JavaScript Engine: Firefox: Firefox: Unspecified vulnerability in JavaScript Engine
JavaScript Engine: Firefox: Firefox: Unspecified vulnerability in JavaScript Engine
A flaw was found in the JavaScript Engine component of Firefox. This issue, while not fully detailed, could potentially lead to an unspecified impact within the browser environment. The exact nature of the vulnerability and its potential for exploitation are not clearly defined in the available information.
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6779
vendor_mozilla·CVSS 5.3
CVE-2026-6779 [MEDIUM] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6779
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6779
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6779
vendor_mozilla·CVSS 5.3
CVE-2026-6779 [MEDIUM] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6779
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6779
Product: Firefox
Impact: high
Fixed in: Firefox 150
VulDB
Mozilla Firefox up to 149 JavaScript Engine Remote Code Execution (Nessus ID 310633)
vuldb·2026-04-28·CVSS 5.3
CVE-2026-6779 [MEDIUM] Mozilla Firefox up to 149 JavaScript Engine Remote Code Execution (Nessus ID 310633)
A vulnerability was found in Mozilla Firefox up to 149. It has been classified as critical. The impacted element is an unknown function of the component JavaScript Engine. The manipulation leads to Remote Code Execution.
This vulnerability is referenced as CVE-2026-6779. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-xp4p-9mc9-5c47: Other issue in the JavaScript Engine component
ghsa_unreviewed·2026-04-21
CVE-2026-6779 [MEDIUM] CWE-20 GHSA-xp4p-9mc9-5c47: Other issue in the JavaScript Engine component
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.
No detection rules found.
No public exploits indexed.
2026-04-21
Published