CVE-2026-6746 is a use-after-free vulnerability in the DOM: Core & HTML component affecting Mozilla Firefox (version 150 and later), Firefox ESR (115.35 and 140.10 and later), Thunderbird (150 and later), and Thunderbird ESR (140.10 and later). This type of vulnerability occurs when an application attempts to access memory that has already been freed, potentially allowing an attacker to execute arbitrary code or cause a denial of service. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, primarily due to its network-based attack vector that requires no user interaction or special privileges. The attack has low complexity and impacts system availability, though confidentiality and integrity are not compromised. The EPSS score of 0.000480000 suggests minimal probability of exploitation in the wild relative to other known vulnerabilities. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from the CISA Known Exploited Vulnerabilities catalog and inactive on the Hot List. This suggests limited community attention and minimal real-world threat posture at this time. Organizations should prioritize patching in accordance with standard update cycles, but this does not require emergency remediation procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.35.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 140.0, < 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.