CVE-2026-74990
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-74990 is a memory corruption vulnerability affecting Mozilla Firefox and Thunderbird, classified as "Internally found bugs" involving evidence of memory corruption or other security-relevant defects. It affects Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0, Firefox 153, Thunderbird ESR 140.13, Thunderbird ESR 153.0, and Thunderbird 153. The vulnerability was discovered internally by Mozilla researchers Christian Holler, Jan de Mooij, and Tom Ritter, and was publicly disclosed on August 18, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory mfsa2026-74, Mozilla Advisory mfsa2026-75).

Technical details

The vulnerability is rooted in improper restriction of operations within the bounds of a memory buffer (CWE-119) and out-of-bounds write (CWE-787), affecting multiple internal components of Firefox and Thunderbird across several ESR branches. Mozilla's internal fuzzing and security review identified multiple bugs — some showing evidence of memory corruption — that were presumed exploitable with sufficient effort. The attack vector is network-based, requires no privileges and no user interaction, making it automatable. No specific technical write-up or public PoC has been released; the underlying bug IDs are tracked in Mozilla Bugzilla (Mozilla Advisory mfsa2026-74, Mozilla Advisory mfsa2026-75).

Impact

Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code, read sensitive data, modify system integrity, or crash the affected application. Given the network-accessible attack vector and lack of required user interaction, the potential for widespread exploitation is significant, with full confidentiality, integrity, and availability impact on affected systems. Both desktop browser (Firefox) and email client (Thunderbird) users across multiple ESR branches are at risk (Mozilla Advisory mfsa2026-75, Feedly).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is reported at 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Mozilla's NVD SSVC assessment classifies exploitation as "none" at this time, though the CVSS score and automatable attack vector indicate high theoretical exploitability (Feedly).

Mitigation and workarounds

Mozilla has released patches addressing CVE-2026-74990 in the following versions: Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird ESR 140.14, and Thunderbird ESR 153.1. Users and administrators should update all affected Firefox and Thunderbird installations to the patched versions immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation (Mozilla Advisory mfsa2026-74, Mozilla Advisory mfsa2026-75, Mozilla Advisory mfsa2026-76).

Community reactions

Mozilla issued coordinated security advisories (MFSA 2026-74 through 2026-80) on August 18, 2026, covering this and related vulnerabilities across Firefox and Thunderbird product lines. Red Hat tracked the issue via Bugzilla and published a corresponding CVE entry. Tenable released Nessus detection plugins (IDs 337625 and 337885) shortly after disclosure. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (Mozilla Advisory mfsa2026-74, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • rhel10::firefox-flatpak
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management