Mozilla disclosed and patched two high-severity vulnerability groups, CVE-2026-5731 and CVE-2026-6786, affecting multiple Firefox and Thunderbird release lines. The flaws were described as memory safety bugs with evidence of memory corruption that could potentially be exploited for arbitrary code execution. Affected versions included Firefox earlier than 149.0.2 and 150, Firefox ESR earlier than 115.34.1, 140.9.1, and 140.10, plus corresponding Thunderbird and Thunderbird ESR releases.
The fixes were shipped across standard and ESR channels in Firefox 149.0.2, Firefox 150, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Firefox ESR 140.10, Thunderbird 149.0.2, Thunderbird 150, and Thunderbird ESR 140.9.1/140.10. The CVE records link the issues to memory-corruption weaknesses including CWE-119, CWE-125, CWE-787, and CWE-416, and assign high-impact CVSS vectors reflecting potential compromise of confidentiality, integrity, and availability if exploited.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-6786 record was created and populated with a description, Bugzilla and Mozilla advisory references, a CVSS v3.1 vector, and CWE classifications including CWE-125, CWE-787, and CWE-416.
Mozilla fixed memory safety bugs tracked as CVE-2026-6786 in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird ESR 140.10. The affected versions included Firefox 149 and ESR 140.9, and Mozilla noted some bugs showed evidence of memory corruption with possible arbitrary code execution impact.
The CVE-2026-5731 entry was updated to add a CVSS v3.1 vector, CWE-119 classification, and links to Mozilla advisory and Bugzilla references documenting the issue and fixes.
Mozilla addressed memory safety bugs tracked as CVE-2026-5731 in Firefox 149.0.2, Firefox ESR 115.34.1 and 140.9.1, and Thunderbird 149.0.2 and ESR 140.9.1. Mozilla said some bugs showed evidence of memory corruption and could potentially be exploited for arbitrary code execution with sufficient effort.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.