CVE-2026-6785General(mozilla / firefox)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for mozilla firefox systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

3.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-125CWE-416CWE-787

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-26: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-05-25: 1Technical Details · 2026-05-25: 104-2605-25
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-05-251
Active Exploitation1
Full discourse2 posts
  • AISecHub@AISecHub
    Active Exploitation

    AI Security Digest | May 18-24, 2026 🔴 ChromaDB: unauthenticated code execution NVD published CVE-2026-45829 for ChromaDB. The bug affects the ChromaDB Python project starting with version 1.0.0. An unauthenticated attacker can send a malicious model repository with trust_remote_code=true to the collections API endpoint and execute code on the server. HiddenLayer assigned the issue a CVSS 4.0 score of 10.0. 📌 https://nvd.nist.gov/vuln/detail/CVE-2026-45829
📌 https://www.hiddenlayer.com/research/chromatoast-served-pre-auth 🟠 Langflow: exploited vulnerability added to CISA KEV CISA added CVE-2025-34291 in Langflow to the Known Exploited Vulnerabilities catalog on May 21. The vulnerability affects Langflow versions up to and including 1.6.9. NVD describes it as a chained issue involving permissive CORS and refresh-token cookie behavior that can lead to account takeover and remote code execution. 📌 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291
📌 https://nvd.nist.gov/vuln/detail/CVE-2025-34291
📌 https://github.com/advisories/GHSA-577h-p2hh-v4mv 🧪 Anthropic: Mythos used for vulnerability discovery Reuters reported that Anthropic planned to brief the Financial Stability Board on vulnerabilities identified by Claude Mythos. Anthropic also published a disclosure dashboard showing 1,596 vulnerabilities disclosed across 281 open-source projects as of May 22. 📌 https://www.reuters.com/technology/anthropic-brief-financial-stability-board-cyber-flaws-exposed-by-mythos-ft-2026-05-18/
📌 https://red.anthropic.com/2026/cvd/
📌 https://www.anthropic.com/research/glasswing-initial-update 🦊 Mozilla: Firefox bugs found during Claude Mythos evaluation Mozilla published details on its work with Anthropic’s Claude Mythos. Firefox 150 included fixes for vulnerabilities identified during the evaluation, grouped under CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. 📌 https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
📌 https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ #AISecurity #CyberSecurity #AISECHUB #ChromaDB #Langflow #CISA #Anthropic #Mythos #Mozilla #Firefox #LLMSecurity

    Post summary

    The post indicates that Langflow’s CVE‑2025‑34291 is actively exploited per CISA, while ChromaDB’s high‑severity CVE‑2026‑45829 is newly disclosed but unproven; Anthropic’s Mythos has identified numerous other vulnerabilities.

    140821.0K
    9.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6785 Memory Safety Bugs in Firefox and Thunderbird ESR Versions 115.34, 140.9, and 149 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6785

    Post summary

    A brief notice that CVE‑2026‑6785 is a memory safety bug affecting certain Firefox and Thunderbird ESR versions, with no further elaboration.

    0000049
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---

Explore more