Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6772

28
FAUCET Score

CVE-2026-6772 is a boundary condition vulnerability within the Libraries component of NSS (Network Security Services) that affects multiple Mozilla products including Firefox 150, Firefox ESR versions 115.35 and 140.10, Thunderbird 150, and Thunderbird 140.10. The flaw stems from incorrect handling of boundary conditions, which could potentially allow unauthorized access to sensitive data. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, indicating significant risk. The attack vector is network-based with low complexity, requires no user interaction, and can be executed without special privileges. The primary impact is confidentiality loss, allowing attackers to access sensitive information, though integrity and availability are not compromised. There is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and remains inactive on security hot lists. The EPSS score of 0.00037 indicates a very low probability of exploitation, suggesting this vulnerability has not yet been leveraged by threat actors despite its availability in the affected products.

Impacted Technologies

VendorProductVersion(s)CPE
< 115.35.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
< 150.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
>= 140.0, < 140.10.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
< 140.10.0CPE matchmatch criteria
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 3rd percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

bugzilla.mozilla.org / show_bug.cgi
Permissions Required
mozilla.org / security/advisories/mfsa2026-30
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-31
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-32
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-33
Vendor Advisory
mozilla.org / security/advisories/mfsa2026-34
Vendor Advisory