CVE-2026-5732: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
Affected products
- Mozilla Firefox: before 140.9.1 (fixed in 140.9.1); before 149.0.2 (fixed in 149.0.2)
Published 2026-04-07. Last modified 2026-07-15.