CVE-2026-6781 is a denial-of-service vulnerability in the Audio/Video Playback component affecting Firefox and Thunderbird, resolved in version 150 of both products. The flaw allows attackers to disrupt service availability without requiring authentication or user interaction. This vulnerability poses a moderate-to-high risk with a CVSS score of 7.5, indicating a network-based attack vector with low complexity that results in high availability impact. The exploitation status remains low, with no evidence of active exploitation in the wild, no known public exploit code, and minimal community attention as indicated by the inactive hot list status and very low EPSS score of 0.0004. Organizations should prioritize patching to Firefox and Thunderbird version 150 as part of routine security updates, though this does not represent an immediate critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.