These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-6749 is a high-severity information disclosure vulnerability in the Firefox browser, caused by uninitialized memory in the Graphics: Canvas2D component. The vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The CVSS score for this vulnerability is 7.5, indicating a high severity. The vulnerability was publicly disclosed on Apr [truncated]
CVE-2026-6748 is a critical vulnerability in the Audio/Video: Web Codecs component of Firefox. The issue arises from uninitialized memory, which could potentially be exploited for code execution. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The CVE was published on April 21, 2026, and last modified on June 30, 2026. The CVSS score for this vulne [truncated]
CVE-2026-6747 is a use-after-free vulnerability in the WebRTC component of Firefox, Thunderbird, and Firefox ESR. The vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. This vulnerability has a CVSS score of 7.5 and a severity of HIGH. The CVE was published on 2026-04-21 and last modified on 2026-06-30. The vulnerability allows for a potential crash and co [truncated]
CVE-2026-6746 is a high-severity use-after-free vulnerability in the DOM: Core & HTML component of Firefox. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE was published on April 21, 2026, and last modified on June 30, 2026.
CVE-2026-5735 is a critical Mozilla vulnerability affecting Firefox 149.0.1 and Thunderbird 149.0.1. The CVE description says the issue involved memory safety bugs, some with evidence of memory corruption, and that Mozilla presumed some could have been exploited to run arbitrary code. Mozilla fixed the problem in Firefox 149.0.2 and Thunderbird 149.0.2. Because NVD rates the issue 9.8 and the CVSS vector [truncated]
CVE-2026-5734 is a critical vulnerability affecting multiple Mozilla products, including Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. The vulnerability is caused by memory safety bugs, some of which showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox 149.0.2 [truncated]
CVE-2026-5733 is a HIGH-severity vulnerability in Mozilla Firefox and Thunderbird, caused by incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The CVE record was published on 2026-04-07T13:16:47.567Z and last modified on 2026-06-30T03:21:09.290Z.
CVE-2026-5732 is a high-severity vulnerability affecting Mozilla Firefox and Thunderbird. The vulnerability is caused by incorrect boundary conditions and integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. User [truncated]
CVE-2026-5731 is a critical vulnerability affecting multiple Mozilla products, including Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. The vulnerability is caused by memory safety bugs, some of which showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fi [truncated]
CVE-2026-4729 is a critical vulnerability affecting Firefox 148 and Thunderbird 148, involving multiple memory safety bugs that could potentially lead to arbitrary code execution. These bugs showed evidence of memory corruption. The vulnerability was fixed in Firefox 149 and Thunderbird 149. Users are advised to update to the latest versions to mitigate this vulnerability. The CVE was published on March 2 [truncated]
CVE-2026-4721 is a critical vulnerability affecting Mozilla Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148, and Thunderbird 148. The vulnerability involves memory safety bugs that show evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, [truncated]
CVE-2026-4720 is a critical vulnerability affecting Mozilla Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148, and Thunderbird 148. The vulnerability involves memory safety bugs that showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9 [truncated]
CVE-2026-4698 is a critical Mozilla JavaScript engine JIT miscompilation issue. According to the published advisory data, the flaw was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Because the CVSS score is 9.8 and the vector is network-reachable with no privileges or user interaction required, this should be treated as an urgent update item for any e [truncated]
CVE-2026-4697 is a HIGH severity vulnerability in Mozilla Firefox, Thunderbird, and Firefox ESR. It relates to incorrect boundary conditions in the Audio/Video: Web Codecs component. This issue was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was publicly disclosed on March 24, 2026, and last modified on June 30, 2026. The CVSS score for this vulnerability is 7.5.
CVE-2026-4695 is a HIGH-severity vulnerability affecting the Audio/Video: Web Codecs component. The issue involves incorrect boundary conditions and was addressed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was publicly disclosed on March 24, 2026, and the CVE record was last modified on June 30, 2026. The CVSS score for this vulnerability is 7.5. The CVE r [truncated]
CVE-2026-4694 is a high-severity vulnerability in Mozilla Firefox, with a CVSS score of 7.5. The vulnerability is caused by incorrect boundary conditions and an integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was published on March 24, 2026, and modified on June 30, 202 [truncated]
CVE-2026-4693 is a HIGH severity vulnerability in the Audio/Video: Playback component. The issue involves incorrect boundary conditions. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The CVE was published on March 24, 2026, and modified on June 30, 2026. The vulnerability has a CVSS score of 7.5 and a CVSS severity of HIGH.
CVE-2026-4692 is a critical vulnerability in the Responsive Design Mode component of Firefox, allowing for sandbox escape. The vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The CVSS score for this vulnerability is 10, indicating the highest severity. The vulnerability was publicly disclosed on March 24, 2026, and the CVE record was l [truncated]
CVE-2026-4689 is a critical vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions and integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. The CVE was published on March 24, 2026, an [truncated]
CVE-2026-4688 is a critical vulnerability in Mozilla Firefox, with a CVSS score of 10. The vulnerability allows for a sandbox escape due to a use-after-free issue in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. The vulnerability was publicly disclosed on March 24, 2026, and last modified on June 30, 2026. The [truncated]
CVE-2026-4687 is a high-severity vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions in the Telemetry component. The vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. This vulnerability has a CVSS score of 8.6 and is classified as HIGH. The CVE was published on March 24, 2026, and last modif [truncated]
CVE-2026-4686 is a HIGH-severity vulnerability in the Graphics: Canvas2D component of Mozilla Firefox, with a CVSS score of 7.5. The vulnerability is caused by incorrect boundary conditions. This issue was addressed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Users should update to the latest versions to mitigate the risk. The CVE was published on March 2 [truncated]
CVE-2026-2807 is a critical vulnerability affecting Firefox 147 and Thunderbird 147, involving memory safety bugs that could lead to arbitrary code execution. The bugs showed evidence of memory corruption, and it is presumed that with enough effort, some of these could have been exploited. The vulnerability was fixed in Firefox 148 and Thunderbird 148. Users are advised to update to the latest versions to [truncated]
CVE-2026-2798 is a high-severity use-after-free vulnerability in the DOM: Core & HTML component of Firefox and Thunderbird. The vulnerability was fixed in Firefox 148 and Thunderbird 148. It has a CVSS score of 8.8 and is classified as HIGH. The vulnerability was published on February 24, 2026, and last modified on June 30, 2026. The CVE record and NVD detail provide further information on this vulnerability.
CVE-2026-2797 is a critical use-after-free vulnerability in the JavaScript: GC component of Firefox and Thunderbird. The vulnerability was fixed in Firefox 148 and Thunderbird 148. This vulnerability has a CVSS score of 9.8 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:28.200Z and last modified on 2026-06-30T03:18:21.253Z. The vulnerability affects Firefox and Thunderbird versions [truncated]
CVE-2026-2796 is a critical vulnerability in the JavaScript: WebAssembly component of Mozilla Firefox and Thunderbird. The vulnerability, which has a CVSS score of 9.8, was fixed in Firefox 148 and Thunderbird 148. This vulnerability involves a Just-In-Time (JIT) miscompilation issue. The CVE was published on February 24, 2026, and last modified on June 30, 2026. The vulnerability affects Firefox versions [truncated]
CVE-2026-2795 is a critical use-after-free vulnerability in the JavaScript: GC component of Firefox and Thunderbird. The vulnerability was fixed in Firefox 148 and Thunderbird 148. It has a CVSS score of 9.8 and a severity of CRITICAL. The vulnerability was publicly disclosed on February 24, 2026, and the CVE record was last modified on June 30, 2026. The vendor, Mozilla, has provided advisories for this [truncated]
CVE-2026-2794 is a high-severity information disclosure vulnerability affecting Firefox and Firefox Focus for Android. The issue arises from uninitialized memory, which could potentially expose sensitive information. This vulnerability was addressed in Firefox version 148. Users are advised to update to the latest version to mitigate this risk. The CVE was published on February 24, 2026, and last modified [truncated]
CVE-2026-2793 is a critical vulnerability affecting multiple Mozilla products, including Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147, and Thunderbird 147. The vulnerability is caused by memory safety bugs, some of which showed evidence of memory corruption. If exploited, these bugs could potentially allow attackers to run arbitrary code. The vulnerability was fixed in Firefox [truncated]
CVE-2026-2792 is a critical vulnerability affecting Mozilla's Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147, and Thunderbird 147. The issue involves memory safety bugs that could lead to memory corruption and potentially allow attackers to execute arbitrary code. This vulnerability was addressed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The CVSS score for this vuln [truncated]