CVE-2026-8961
published 2026-05-19CVE-2026-8961: Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.32%
24.4th percentile
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 151 | Firefox 151 |
| mozilla | firefox | < 140.11.0 | 140.11.0 |
| mozilla | firefox | < 151.0.0 | 151.0.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < Firefox ESR 140.11 | Firefox ESR 140.11 |
| mozilla | thunderbird | < Thunderbird 151 | Thunderbird 151 |
| mozilla | thunderbird | < Thunderbird 140.11 | Thunderbird 140.11 |
| mozilla | thunderbird | < 140.11 | 140.11 |
| mozilla | thunderbird | < 151.0.0 | 151.0.0 |
| rhel10 | firefox-flatpak | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: Spoofing issue in the Form Autofill component
vendor_redhat·2026-05-19·CVSS 6.5
CVE-2026-8961 [MEDIUM] CWE-472 firefox: Spoofing issue in the Form Autofill component
firefox: Spoofing issue in the Form Autofill component
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Spoofing issue in the Form Autofill component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 7) - Affected
Package: firefox (Red Hat Enterprise Linux 8) - Affected
Package: firefox (Red Hat Enterprise Linux 9) - Affected
Mozilla
Mozilla Foundation Security Advisory 2026-50: CVE-2026-8961
vendor_mozilla
CVE-2026-8961 Mozilla Foundation Security Advisory 2026-50: CVE-2026-8961
Mozilla Foundation Security Advisory 2026-50
CVE: CVE-2026-8961
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 151
Mozilla
Mozilla Foundation Security Advisory 2026-51: CVE-2026-8961
vendor_mozilla
CVE-2026-8961 Mozilla Foundation Security Advisory 2026-51: CVE-2026-8961
Mozilla Foundation Security Advisory 2026-51
CVE: CVE-2026-8961
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.11
Mozilla
Mozilla Foundation Security Advisory 2026-46: CVE-2026-8961
vendor_mozilla
CVE-2026-8961 Mozilla Foundation Security Advisory 2026-46: CVE-2026-8961
Mozilla Foundation Security Advisory 2026-46
CVE: CVE-2026-8961
Product: Firefox
Impact: high
Fixed in: Firefox 151
Mozilla
Mozilla Foundation Security Advisory 2026-48: CVE-2026-8961
vendor_mozilla
CVE-2026-8961 Mozilla Foundation Security Advisory 2026-48: CVE-2026-8961
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8961
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
VulDB
Mozilla Firefox up to 140.10/150 Form Autofill
vuldb·2026-05-19
CVE-2026-8961 [LOW] Mozilla Firefox up to 140.10/150 Form Autofill
A vulnerability was found in Mozilla Firefox up to 140.10/150. It has been rated as problematic. The impacted element is an unknown function of the component Form Autofill. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2026-8961. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-5qxp-cr8v-39px: Spoofing issue in the Form Autofill component
ghsa_unreviewed·2026-05-19
CVE-2026-8961 [MEDIUM] CWE-290 GHSA-5qxp-cr8v-39px: Spoofing issue in the Form Autofill component
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8961 firefox: Spoofing issue in the Form Autofill component
bugzilla·2026-05-19·CVSS 6.5
CVE-2026-8961 [MEDIUM] CVE-2026-8961 firefox: Spoofing issue in the Form Autofill component
CVE-2026-8961 firefox: Spoofing issue in the Form Autofill component
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
Bugzilla
CVE-2025-8961 mingw-libtiff: LibTIFF memory corruption [fedora-42]
bugzilla·2025-08-14·CVSS 1.9
CVE-2025-8961 [LOW] CVE-2025-8961 mingw-libtiff: LibTIFF memory corruption [fedora-42]
CVE-2025-8961 mingw-libtiff: LibTIFF memory corruption [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases
Bugzilla
CVE-2025-8961 iv: LibTIFF memory corruption [fedora-42]
bugzilla·2025-08-14·CVSS 1.9
CVE-2025-8961 [LOW] CVE-2025-8961 iv: LibTIFF memory corruption [fedora-42]
CVE-2025-8961 iv: LibTIFF memory corruption [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are n
2026-05-19
Published