
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-74968 is a site isolation issue in the Graphics: WebRender component of Mozilla Firefox and Thunderbird, classified as an Origin Validation Error (CWE-346). Discovered and reported by researcher "kiyong," it was publicly disclosed on August 18, 2026, as part of Mozilla's security advisory releases. Affected products include Firefox versions prior to 154, Firefox ESR versions prior to 153.1, Thunderbird versions prior to 154, and Thunderbird ESR versions prior to 153.1. It carries a CVSS v3.1 base score of 5.4 (Medium) (Mozilla Advisory, Feedly).
The vulnerability is rooted in an origin validation error (CWE-346) within Firefox's WebRender graphics rendering component, which is responsible for GPU-accelerated page rendering. The flaw allows content from one origin to improperly interact with or observe rendering artifacts from a different origin, breaking site isolation guarantees. Exploitation requires user interaction (e.g., visiting a malicious web page) and is network-based with low attack complexity and no privileges required. The underlying bug is tracked as Mozilla Bug 2055738 (Mozilla Advisory, Mozilla Advisory ESR).
Successful exploitation of this vulnerability can result in limited confidentiality and integrity impacts — specifically, an attacker-controlled origin may be able to read or influence rendered content belonging to a different origin, potentially leaking sensitive information displayed in another tab or frame. The CVSS assessment indicates no availability impact, and the scope is unchanged, meaning the attack is confined to the browser's rendering process without enabling full system compromise or lateral movement. In Thunderbird, the risk is further reduced because scripting is disabled when reading mail, limiting exploitation to browser-like contexts (Mozilla Advisory, Mozilla Advisory).
As of the disclosure date, there is no evidence of in-the-wild exploitation, no public proof-of-concept code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable, with only partial technical impact. The EPSS score is reported as 0.0, reflecting a very low probability of near-term exploitation (Feedly).
Mozilla has released patched versions addressing this vulnerability: Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1. Users and administrators should update to these versions or later immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation (Mozilla Advisory, Mozilla Advisory ESR, Mozilla Advisory TB).
Mozilla disclosed this vulnerability as part of a large batch of security fixes in the Firefox 154 and Firefox ESR 153.1 release cycle on August 18, 2026, with no specific vendor statement singling out CVE-2026-74968 beyond the advisory listing. No notable independent researcher commentary or significant media coverage specific to this CVE has been identified, consistent with its moderate severity rating among a larger set of disclosed issues.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."