CVE-2026-6786General(mozilla / firefox)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-416CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-26: 1Mentions · 2026-05-03: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-25: 104-2605-0305-25
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-05-031
Disclosure1
2026-05-251
General1
Full discourse3 posts
  • AISecHub@AISecHub
    General

    AI Security Digest | May 18-24, 2026 🔴 ChromaDB: unauthenticated code execution NVD published CVE-2026-45829 for ChromaDB. The bug affects the ChromaDB Python project starting with version 1.0.0. An unauthenticated attacker can send a malicious model repository with trust_remote_code=true to the collections API endpoint and execute code on the server. HiddenLayer assigned the issue a CVSS 4.0 score of 10.0. 📌 https://nvd.nist.gov/vuln/detail/CVE-2026-45829
📌 https://www.hiddenlayer.com/research/chromatoast-served-pre-auth 🟠 Langflow: exploited vulnerability added to CISA KEV CISA added CVE-2025-34291 in Langflow to the Known Exploited Vulnerabilities catalog on May 21. The vulnerability affects Langflow versions up to and including 1.6.9. NVD describes it as a chained issue involving permissive CORS and refresh-token cookie behavior that can lead to account takeover and remote code execution. 📌 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291
📌 https://nvd.nist.gov/vuln/detail/CVE-2025-34291
📌 https://github.com/advisories/GHSA-577h-p2hh-v4mv 🧪 Anthropic: Mythos used for vulnerability discovery Reuters reported that Anthropic planned to brief the Financial Stability Board on vulnerabilities identified by Claude Mythos. Anthropic also published a disclosure dashboard showing 1,596 vulnerabilities disclosed across 281 open-source projects as of May 22. 📌 https://www.reuters.com/technology/anthropic-brief-financial-stability-board-cyber-flaws-exposed-by-mythos-ft-2026-05-18/
📌 https://red.anthropic.com/2026/cvd/
📌 https://www.anthropic.com/research/glasswing-initial-update 🦊 Mozilla: Firefox bugs found during Claude Mythos evaluation Mozilla published details on its work with Anthropic’s Claude Mythos. Firefox 150 included fixes for vulnerabilities identified during the evaluation, grouped under CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. 📌 https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
📌 https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ #AISecurity #CyberSecurity #AISECHUB #ChromaDB #Langflow #CISA #Anthropic #Mythos #Mozilla #Firefox #LLMSecurity

    Post summary

    The digest reports a new unauthenticated code‑execution flaw (CVE‑2026‑45829) in ChromaDB, confirms active exploitation of a Langflow vulnerability (CVE‑2025‑34291) via the CISA KEV catalog, and notes that Firefox 150 has patched multiple Mythos‑discovered vulnerabilities.

    140821.0K
    9.3K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-6786: Memory Safety Vulnerabilities in Mozilla Products - What It Means for Your Business and How to Respond https://hubs.li/Q04fd35H0

    Post summary

    The post announces a memory-safety issue in Mozilla products (CVE‑2026‑6786) and offers general guidance for businesses, but provides no technical details, PoC, or exploitation evidence.

    0000028
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6786 Memory Safety Bugs in Firefox and Thunderbird 140.9 and 149 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6786

    Post summary

    The brief notice merely announces CVE-2026-6786 as a memory safety bug affecting Firefox and Thunderbird without offering exploitation details, remediation guidance, or evidence of active attacks.

    0000060
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---

Explore more