CVE-2026-6780
published 2026-04-21CVE-2026-6780: Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.29%
21.3th percentile
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 149 Playback denial of service (Nessus ID 310622 / WID-SEC-2026-1228)
vuldb·2026-05-21·CVSS 7.5
CVE-2026-6780 [HIGH] Mozilla Firefox up to 149 Playback denial of service (Nessus ID 310622 / WID-SEC-2026-1228)
A vulnerability was found in Mozilla Firefox up to 149. It has been declared as problematic. This affects an unknown function of the component Playback. The manipulation results in denial of service.
This vulnerability is identified as CVE-2026-6780. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-47f5-x8gg-g88g: Denial-of-service in the Audio/Video: Playback component
ghsa_unreviewed·2026-04-21
CVE-2026-6780 [HIGH] CWE-400 GHSA-47f5-x8gg-g88g: Denial-of-service in the Audio/Video: Playback component
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150.
Red Hat
firefox: Firefox: Denial of Service in Audio/Video Playback component
vendor_redhat·2026-04-21·CVSS 7.5
CVE-2026-6780 [HIGH] CWE-770 firefox: Firefox: Denial of Service in Audio/Video Playback component
firefox: Firefox: Denial of Service in Audio/Video Playback component
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
A flaw was found in Firefox. This vulnerability, located in the Audio/Video: Playback component, could allow an attacker to trigger a denial of service (DoS). A denial of service attack can make the affected system or application unavailable to legitimate users.
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6780
vendor_mozilla·CVSS 7.5
CVE-2026-6780 [HIGH] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6780
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6780
Product: Firefox
Impact: high
Fixed in: Firefox 150
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6780
vendor_mozilla·CVSS 7.5
CVE-2026-6780 [HIGH] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6780
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6780
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
No detection rules found.
No public exploits indexed.
2026-04-21
Published