Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6749

27
FAUCET Score

CVE-2026-6749 is an information disclosure vulnerability in the Graphics Canvas2D component of Mozilla Firefox and Thunderbird caused by uninitialized memory, potentially allowing attackers to access sensitive data. The vulnerability affects Firefox versions prior to 150, Firefox ESR versions prior to 115.35 and 140.10, and Thunderbird versions prior to 150 and 140.10. The flaw was patched across all supported product lines in coordinated security updates. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, reflecting a network-based attack vector requiring no privileges or user interaction. The attack complexity is low, indicating ease of exploitation, though the impact is limited to confidentiality with no integrity or availability concerns. The moderate FAUCET Risk Score of 47.0 suggests moderate organizational concern, though EPSS scoring indicates minimal real-world prevalence. There is currently no evidence of active exploitation in the wild, with no public exploit code availability and the vulnerability remaining inactive on known exploit lists. The low EPSS score and absence from the Known Exploited Vulnerabilities catalog suggest this vulnerability has not gained significant community or attacker attention. Organizations should prioritize patching based on standard update cycles rather than emergency response protocols.

Impacted Technologies

VendorProductVersion(s)CPE
< 115.35.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
< 150.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
>= 140.0, < 140.10.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
< 140.10.0CPE matchmatch criteria
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
33.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 12th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

mozillavendor investigatingvia nvd_reference
View patch

References

access.redhat.com / errata/RHSA-2026:10757
access.redhat.com / errata/RHSA-2026:10766
access.redhat.com / errata/RHSA-2026:10767
access.redhat.com / errata/RHSA-2026:12285
access.redhat.com / errata/RHSA-2026:13537
access.redhat.com / errata/RHSA-2026:15892
access.redhat.com / errata/RHSA-2026:17477
access.redhat.com / errata/RHSA-2026:17687
access.redhat.com / errata/RHSA-2026:17688
access.redhat.com / errata/RHSA-2026:17689
access.redhat.com / errata/RHSA-2026:17690
access.redhat.com / errata/RHSA-2026:19041
access.redhat.com / errata/RHSA-2026:19131
access.redhat.com / errata/RHSA-2026:19201
access.redhat.com / errata/RHSA-2026:19348
access.redhat.com / errata/RHSA-2026:19461
access.redhat.com / errata/RHSA-2026:19462
access.redhat.com / errata/RHSA-2026:19463
access.redhat.com / errata/RHSA-2026:19464
access.redhat.com / errata/RHSA-2026:19465
access.redhat.com / errata/RHSA-2026:19466
access.redhat.com / errata/RHSA-2026:19467
access.redhat.com / errata/RHSA-2026:19468
access.redhat.com / errata/RHSA-2026:19469
access.redhat.com / errata/RHSA-2026:19542
access.redhat.com / errata/RHSA-2026:19655
access.redhat.com / errata/RHSA-2026:19704
access.redhat.com / security/cve/CVE-2026-6749
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-6749.json
bugzilla.mozilla.org / show_bug.cgi
Permissions Required
mozilla.org / security/advisories/mfsa2026-30
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-31
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-32
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-33
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-34
Vendor Advisory