Memory Safety Issues in Firefox ESR and Firefox Products by Mozilla
CVE-2026-8974

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8974?

Mozilla Firefox ESR versions 140.10 and Firefox 150 contain critical memory safety bugs that may lead to memory corruption, potentially allowing attackers to execute arbitrary code with sufficient effort. These vulnerabilities have been addressed in the latest updates with Firefox version 151 and Firefox ESR 140.11, emphasizing the importance of keeping software up to date to mitigate security risks.

Affected Version(s)

Firefox 140.11

Firefox 151

Thunderbird 140.11

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nika Layzell, Randell Jesup, Timothy Nikkel, Tom Schuster and the Mozilla Fuzzing Team
.