CVE-2026-6784General(mozilla / firefox)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-416CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-05-25: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-05-25: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-25: 104-2104-2205-25
Signal classification3 categories
General
133.3%
PoC
133.3%
Disclosure
133.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-211
General1
2026-04-221
PoC1
2026-05-251
Disclosure1
Full discourse3 posts
  • AISecHub@AISecHub
    Disclosure

    AI Security Digest | May 18-24, 2026 🔴 ChromaDB: unauthenticated code execution NVD published CVE-2026-45829 for ChromaDB. The bug affects the ChromaDB Python project starting with version 1.0.0. An unauthenticated attacker can send a malicious model repository with trust_remote_code=true to the collections API endpoint and execute code on the server. HiddenLayer assigned the issue a CVSS 4.0 score of 10.0. 📌 https://nvd.nist.gov/vuln/detail/CVE-2026-45829
📌 https://www.hiddenlayer.com/research/chromatoast-served-pre-auth 🟠 Langflow: exploited vulnerability added to CISA KEV CISA added CVE-2025-34291 in Langflow to the Known Exploited Vulnerabilities catalog on May 21. The vulnerability affects Langflow versions up to and including 1.6.9. NVD describes it as a chained issue involving permissive CORS and refresh-token cookie behavior that can lead to account takeover and remote code execution. 📌 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291
📌 https://nvd.nist.gov/vuln/detail/CVE-2025-34291
📌 https://github.com/advisories/GHSA-577h-p2hh-v4mv 🧪 Anthropic: Mythos used for vulnerability discovery Reuters reported that Anthropic planned to brief the Financial Stability Board on vulnerabilities identified by Claude Mythos. Anthropic also published a disclosure dashboard showing 1,596 vulnerabilities disclosed across 281 open-source projects as of May 22. 📌 https://www.reuters.com/technology/anthropic-brief-financial-stability-board-cyber-flaws-exposed-by-mythos-ft-2026-05-18/
📌 https://red.anthropic.com/2026/cvd/
📌 https://www.anthropic.com/research/glasswing-initial-update 🦊 Mozilla: Firefox bugs found during Claude Mythos evaluation Mozilla published details on its work with Anthropic’s Claude Mythos. Firefox 150 included fixes for vulnerabilities identified during the evaluation, grouped under CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. 📌 https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
📌 https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ #AISecurity #CyberSecurity #AISECHUB #ChromaDB #Langflow #CISA #Anthropic #Mythos #Mozilla #Firefox #LLMSecurity

    Post summary

    The digest announces new CVE-2026-45829 for ChromaDB with detailed exploitation vectors, reports active exploitation of CVE-2025-34291 in Langflow per CISA, and notes that Mozilla Firefox 150 includes fixes for Mythos‑identified bugs.

    140821.0K
    9.3K followersView on X
  • CypherByte@cypherbyteio
    PoC

    our browser is the front door to your OS. Is it locked? 🦊🔓 A critical memory safety vulnerability (CVE-2026-6784) in Firefox 149 allows unauthenticated attackers to achieve Remote Code Execution (RCE). A single malicious site can now compromise your entire system. Memory corruption isn't just a bug; it's a weapon. Patch immediately to stay ahead of the exploit. 🛡️ Full Technical PoC: https://www.cypherbyte.io/blog/cve-2026-6784-firefox-149-memory-safety-rce/ Follow @cypherbyteio 🛡️ #Firefox #RCE #CyberSecurity #ZeroDay #InfoSec

    Post summary

    A critical memory safety flaw (CVE-2026-6784) in Firefox 149 can lead to unauthenticated RCE, with a publicly available PoC and a call for immediate patching.

    1000076
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6784 Memory Safety Bugs in Firefox 149 and Thunderbird 149 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6784

    Post summary

    The post lists CVE-2026-6784 as a memory safety bug in Firefox 149 and Thunderbird 149, linking to a Vulmon page for further details without providing additional technical or exploit information.

    0000033
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillathunderbird---

Explore more