CVE-2026-74989: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

Affected products

  • Mozilla Firefox: before 154.0.0 (fixed in 154.0.0)
  • Mozilla Thunderbird: before 154.0 (fixed in 154.0)

Published 2026-08-18. Last modified 2026-09-01.