CVE-2026-2759Disclosure(mozilla / firefox)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1384

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-28); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-27: 1Mentions · 2026-02-28: 3Mentions · 2026-03-01: 1Technical Details · 2026-02-28: 3Technical Details · 2026-03-01: 102-2702-2803-01
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-271
General1
2026-02-283
Disclosure3
2026-03-011
Disclosure1
Full discourse5 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Mozilla ❗ CVE-2026-2759 ❗ CVE-2026-2758 ❗ CVE-2026-2757 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mozilla-8/ https://t.co/7PsTRT1nPC

    Post summary

    The tweet lists three Mozilla product CVEs and links to a site for more information, but offers no further technical or exploit details.

    00001106
    6.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2759 (CVSS:9.8, CRITICAL) is Modified. Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR..https://nvd.nist.gov/vuln/detail/CVE-2026-2759 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2759, a critical boundary‑condition flaw in Firefox’s ImageLib component (CVSS 9.8), affecting versions below 148 and ESR, but offers no PoC, exploit, or patch details.

    0000026
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2759 Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8. https://www.cve.org/CVERecord?id=CVE-2026-2759 ----- Traducción: CVE-2026-2759 Condiciones de lím… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2759, noting affected Firefox versions and a boundary‑condition flaw in the ImageLib component, but offers no PoC, exploit, or mitigation details.

    0000042
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2759 Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8. https://www.cve.org/CVERecord?id=CVE-2026-2759

    Post summary

    The text announces CVE-2026-2759, a boundary condition flaw in Firefox's ImageLib component affecting specific Firefox and ESR versions.

    00000624
    56.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2759 (CVSS:9.8, CRITICAL) is Modified. Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR..https://nvd.nist.gov/vuln/detail/CVE-2026-2759 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-2759 is a newly disclosed critical flaw in Firefox's Graphics ImageLib component involving incorrect boundary conditions, with no information on PoCs, exploitation, patches, or active attacks.

    0000034
    173 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more