CVE-2026-12289Patch(mozilla / firefox)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-07-05)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-25: 1Mentions · 2026-07-05: 2Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-05: 2Technical Details · 2026-06-25: 1Technical Details · 2026-07-05: 206-2507-05
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-251
Patch1
2026-07-052
Patch2
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:33445 – Thunderbird 140.12.0-1.el8_10 liberado para Rocky Linux 8. Corrige 15+ CVEs, incluindo CVE-2026-12289 (escalação de privilégio) e CVE-2026-12294 (sandbox escape). Saiba mais: -> http://tinyurl.com/4hjszp5x https://t.co/9YM2aUNCVx

    Post summary

    A new Thunderbird package has been released for Rocky Linux 8, addressing 15+ CVEs including privilege escalation and sandbox escape vulnerabilities.

    10000118
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:33445 – Thunderbird 140.12.0-1.el8_10 liberado para Rocky Linux 8. Corrige 15+ CVEs, incluindo CVE-2026-12289 (escalação de privilégio) e CVE-2026-12294 (sandbox escape). Saiba mais: -> http://tinyurl.com/4hjszp5x https://t.co/ZAdXuigaCt

    Post summary

    A security advisory issued a Thunderbird update for Rocky Linux 8 that resolves more than 15 CVEs, including privilege escalation and sandbox escape vulnerabilities.

    10000107
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    RLSA-2026-27717: Firefox 140.12.0 corrige 30+ CVEs críticos no Rocky Linux 8, incluindo RCE (CVE-2026-12289/12291), sandbox escape (CVE-2026-12294/12295) e memory safety bugs. Saiba mais: -> http://tinyurl.com/4ry83bep #RockyLinux #Firefox https://t.co/MESi906b3p

    Post summary

    The tweet announces that Firefox 140.12.0 for Rocky Linux 8 fixes more than 30 critical CVEs, including RCE and sandbox escape bugs, and points to a link for additional details.

    1000066
    1.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more