CVE-2026-6772 is a boundary condition vulnerability within the Libraries component of NSS (Network Security Services) that affects multiple Mozilla products including Firefox 150, Firefox ESR versions 115.35 and 140.10, Thunderbird 150, and Thunderbird 140.10. The flaw stems from incorrect handling of boundary conditions, which could potentially allow unauthorized access to sensitive data. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, indicating significant risk. The attack vector is network-based with low complexity, requires no user interaction, and can be executed without special privileges. The primary impact is confidentiality loss, allowing attackers to access sensitive information, though integrity and availability are not compromised. There is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and remains inactive on security hot lists. The EPSS score of 0.00037 indicates a very low probability of exploitation, suggesting this vulnerability has not yet been leveraged by threat actors despite its availability in the affected products.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.35.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 140.0, < 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.