Memory Safety Issues in Firefox ESR and Standard Versions
CVE-2026-8975

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8975?

Memory safety issues identified in various versions of Firefox, including Firefox ESR 115.35, Firefox ESR 140.10, and Firefox 150, revealed potential memory corruption risks. With sufficient exploitation effort, these vulnerabilities could allow unauthorized arbitrary code execution. The issues have been addressed in the latest updates, specifically Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11, enhancing user security and product stability.

Affected Version(s)

Firefox 115.36

Firefox 140.11

Firefox 151

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew McCreight, Valentin Gosu, Nika Layzell, Tom Schuster and the Mozilla Fuzzing Team
.