CVE-2026-6784
published 2026-04-21CVE-2026-6784: Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
PriorityP342high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.30%
22.1th percentile
Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Firefox: Thunderbird: Firefox and Thunderbird: Arbitrary code execution via memory safety bugs
vendor_redhat·2026-04-21·CVSS 7.5
CVE-2026-6784 [HIGH] CWE-787 Firefox: Thunderbird: Firefox and Thunderbird: Arbitrary code execution via memory safety bugs
Firefox: Thunderbird: Firefox and Thunderbird: Arbitrary code execution via memory safety bugs
A flaw was found in Firefox and Thunderbird. These memory safety bugs could lead to memory corruption. With sufficient effort, an attacker could potentially exploit these issues to execute arbitrary code, gaining unauthorized control over the affected system.
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6784
vendor_mozilla·CVSS 7.5
CVE-2026-6784 [HIGH] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6784
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6784
Product: Firefox
Impact: high
Fixed in: Firefox 150
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6784
vendor_mozilla·CVSS 7.5
CVE-2026-6784 [HIGH] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6784
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6784
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
VulDB
Mozilla Firefox up to 149 memory corruption (Nessus ID 307899 / WID-SEC-2026-1228)
vuldb·2026-05-21·CVSS 7.5
CVE-2026-6784 [HIGH] Mozilla Firefox up to 149 memory corruption (Nessus ID 307899 / WID-SEC-2026-1228)
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 149. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2026-6784. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-fcrv-8vh3-4pg3: Memory safety bugs present in Firefox 149 and Thunderbird 149
ghsa_unreviewed·2026-04-21
CVE-2026-6784 [HIGH] CWE-125 GHSA-fcrv-8vh3-4pg3: Memory safety bugs present in Firefox 149 and Thunderbird 149
Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1536243%2C1745382%2C1851073%2C1893400%2C1963301%2C2001319%2C2002899%2C2012436%2C2014435%2C2016901%2C2019916%2C2020486%2C2020612%2C2020817%2C2021788%2C2022051%2C2022367%2C2022431%2C2023302%2C2023670%2C2024225%2C2024238%2C2024240%2C2024265%2C2024367%2C2024369%2C2024424%2C2024760%2C2025281%2C2025361%2C2025387%2C2025466%2C2025954%2C2025958%2C2026278%2C2026292%2C2026297%2C2026378%2C2027148%2C2027287%2C2027341%2C2027384%2C2027427%2C2027694%2C2027993%2C2028009%2C2028270%2C2028416%2C2028524%2C2029295%2C2029699%2C2029800%2C2029801https://www.mozilla.org/security/advisories/mfsa2026-30/https://www.mozilla.org/security/advisories/mfsa2026-33/https://access.redhat.com/security/cve/CVE-2026-6784https://bugzilla.redhat.com/show_bug.cgi?id=2460084https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6784.json
2026-04-21
Published