CVE-2026-5735
Last modified
CVE-2026-5735 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 149.0.2 |
| Mozilla | Thunderbird | < 149.0.2 |
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025475%2C2025477Broken Link, Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2026-25/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-5735?
How severe is CVE-2026-5735?
How do I fix CVE-2026-5735?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57344Unauthenticated Cross Site Scripting (XSS) in Classified Lis…7.1
- CVE-2026-57345Unauthenticated Cross Site Scripting (XSS) in Internal Links…7.1
- CVE-2026-57346Improper Limitation of a Pathname to a Restricted Directory …7.1
- CVE-2026-57347Subscriber Sensitive Data Exposure in Hotel Booking Lite <= …6.5
- CVE-2026-57348Unauthenticated Server Side Request Forgery (SSRF) in Paid M…7.2
- CVE-2026-57349Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS …7.1
- CVE-2026-57350Unauthenticated Cross Site Scripting (XSS) in WP Debugging <…7.1
- CVE-2026-57351Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grab…7.1
- CVE-2026-57352Unauthenticated Broken Authentication in ALD – Dropshipping …4.8
- CVE-2026-57353Subscriber Broken Access Control in Link Whisper Premium <= …6.5
- CVE-2026-57354Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0…6.5
- CVE-2026-57355Subscriber Broken Access Control in Classified Listing <= 5.…6.5
Are you affected by CVE-2026-5735?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
