- CVE ID
- CVE-2026-8974
- CVE Description
- Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- Published
- May 20, 2026
- CVSS Score & Severity
8.8High
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS Score
- 0.045%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database