CVE-2026-74990
NixOS 취약성 분석 및 완화

개요

CVE-2026-74990 is a memory corruption vulnerability affecting Mozilla Firefox and Thunderbird, classified as "Internally found bugs" involving evidence of memory corruption or other security-relevant defects. It affects Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0, Firefox 153, Thunderbird ESR 140.13, Thunderbird ESR 153.0, and Thunderbird 153. The vulnerability was discovered internally by Mozilla researchers Christian Holler, Jan de Mooij, and Tom Ritter, and was publicly disclosed on August 18, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory mfsa2026-74, Mozilla Advisory mfsa2026-75).

기술적 세부 사항

The vulnerability is rooted in improper restriction of operations within the bounds of a memory buffer (CWE-119) and out-of-bounds write (CWE-787), affecting multiple internal components of Firefox and Thunderbird across several ESR branches. Mozilla's internal fuzzing and security review identified multiple bugs — some showing evidence of memory corruption — that were presumed exploitable with sufficient effort. The attack vector is network-based, requires no privileges and no user interaction, making it automatable. No specific technical write-up or public PoC has been released; the underlying bug IDs are tracked in Mozilla Bugzilla (Mozilla Advisory mfsa2026-74, Mozilla Advisory mfsa2026-75).

영향

Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code, read sensitive data, modify system integrity, or crash the affected application. Given the network-accessible attack vector and lack of required user interaction, the potential for widespread exploitation is significant, with full confidentiality, integrity, and availability impact on affected systems. Both desktop browser (Firefox) and email client (Thunderbird) users across multiple ESR branches are at risk (Mozilla Advisory mfsa2026-75, Feedly).

악용 가능성

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is reported at 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Mozilla's NVD SSVC assessment classifies exploitation as "none" at this time, though the CVSS score and automatable attack vector indicate high theoretical exploitability (Feedly).

완화 및 해결 방법

Mozilla has released patches addressing CVE-2026-74990 in the following versions: Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird ESR 140.14, and Thunderbird ESR 153.1. Users and administrators should update all affected Firefox and Thunderbird installations to the patched versions immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation (Mozilla Advisory mfsa2026-74, Mozilla Advisory mfsa2026-75, Mozilla Advisory mfsa2026-76).

커뮤니티 반응

Mozilla issued coordinated security advisories (MFSA 2026-74 through 2026-80) on August 18, 2026, covering this and related vulnerabilities across Firefox and Thunderbird product lines. Red Hat tracked the issue via Bugzilla and published a corresponding CVE entry. Tenable released Nessus detection plugins (IDs 337625 and 337885) shortly after disclosure. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (Mozilla Advisory mfsa2026-74, Red Hat CVE).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 NixOS 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
아니요Aug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
아니요Aug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
아니요Aug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
아니요Aug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
아니요Aug 18, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자