Memory Corruption Vulnerabilities in Firefox and Firefox ESR
CVE-2026-74987

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74987?

Recent internally identified bugs in Firefox and Firefox ESR versions have revealed potential memory corruption vulnerabilities. The weaknesses, present in Firefox ESR 140.13, Firefox ESR 153.0, and Firefox 153, could be leveraged if sufficient effort is expended to exploit them. These issues have been addressed in the subsequent updates of Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1, mitigating the risk posed to users.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
.