CVE-2026-8091Patch(mozilla / firefox)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754CWE-805

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-15)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-07: 1Mentions · 2026-05-10: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 2Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 105-0705-1005-1405-15
Signal classification2 categories
Patch
360.0%
General
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-071
Patch1
2026-05-101
Patch1
2026-05-141
Patch1
2026-05-152
General2
Full discourse5 posts
  • Sami Laiho@samilaiho
    Patch

    Mozilla Firefox, Thunderbird: Multiple issues resolved URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8091 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8

    Post summary

    Mozilla has released an official fix for CVE-2026-8091, which is classified as critical with a 9.8 CVSS score; no proof‑of‑concept, exploit, or active exploitation was reported.

    040811.2K
    30.6K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-8091 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The statement lists a new CVE with a critical CVSS score but offers no PoC, exploit details, or patch information.

    1000034
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-8091-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content merely links to a CVE‑2026‑8091 advisory without providing any explicit technical or actionable details.

    0000023
    226 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Patch

    Update Firefox. Mozilla fixed CVE-2026-8091 — a CVSS 9.8 bug in audio/video playback that lets a malicious page run code. Patched in Firefox 150, Thunderbird 150, and ESR 140.10.1 / 115.35.2. https://nvd.nist.gov/vuln/detail/CVE-2026-8091

    Post summary

    Mozilla released updates patching CVE-2026-8091, a high‑severity audio/video playback bug that could enable code execution; the update applies to recent Firefox and Thunderbird builds.

    0000052
    35 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-8091 Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 140.10.2 and Firefox ESR 115.35.2. https://www.cve.org/CVERecord?id=CVE-2026-8091

    Post summary

    CVE-2026-8091 involves boundary condition flaws in Firefox's Audio/Video playback component and has been patched in ESR 140.10.2 and 115.35.2; no PoC or exploit details are provided.

    0000049
    57.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillathunderbird---

Explore more