CVE-2026-15719
Last modified
CVE-2026-15719 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 152.0.6 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2043820Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2026-67/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-15719?
How severe is CVE-2026-15719?
How do I fix CVE-2026-15719?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15711A vulnerability was found in libsoup's WebSocket frame parsi…7.5
- CVE-2026-15712A heap buffer over-read vulnerability was discovered in libs…5.9
- CVE-2026-15713A vulnerability was found in libsoup's HTTP/2 protocol imple…5.9
- CVE-2026-15714An out-of-bounds read vulnerability was found in libsoup's m…6.5
- CVE-2026-15715A vulnerability was identified in SourceCodester Class and E…4.3
- CVE-2026-15718We are aware that exploit code for this is public however we…4.3
- CVE-2026-1572The Livemesh Addons for Elementor plugin for WordPress is vu…6.4
- CVE-2026-15720In Open5GS through version 2.7.7 a pre-authentication heap o…8.6
- CVE-2026-15721Cleartext storage of sensitive information vulnerability in …9.8
- CVE-2026-15722A stack buffer overflow flaw was found in 389 Directory Serv…7.5
- CVE-2026-15724In Progress ShareFile Storage Zones Controller versions prio…8.7
- CVE-2026-15727The WP Bulk Delete plugin for WordPress is vulnerable to gen…4.9
Are you affected by CVE-2026-15719?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
