Description
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in the graphics text rendering subsystem of Mozilla. It can corrupt memory during text rendering. The CVE description does not claim a confirmed execution path, so the exact impact is uncertain; memory corruption could lead to crashes or, in severe cases, arbitrary code execution.

Affected Systems

Mozilla Firefox browsers and Thunderbird email clients, including both stable and ESR branches, are affected. All versions prior to Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1 are vulnerable, as the fix was applied only in those releases and newer ones.

Risk and Exploitability

Mozilla Firefox browsers and Thunderbird email clients, including both stable and ESR branches, are affected. All versions prior to Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1 are vulnerable. The EPSS score of < 1% and the fact that the CVE is not listed in the CISA KEV catalog mean the exact probability of exploitation is unclear, but the CVSS score of 9.8 indicates a critical severity if exploited. A use‑after‑free flaw in a graphics component can usually be triggered by rendering malicious content from a webpage, which is inferred from the component’s role; however, exploitation would require the browser to process the offending content. The potential impact is high if the flaw is successfully leveraged.

Generated by OpenCVE AI on August 21, 2026 at 17:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox 154 or newer, or the latest ESR release (115.39, 140.14, or 153.1) that contains the fix.
  • Update to Thunderbird 154 or newer, or the latest ESR release (140.14, 153.1) that contains the fix.
  • Restart the browser after updating to ensure the new binary is running.
  • Restart Thunderbird after updating to ensure the new binary is running.
  • If an immediate update is not possible, consider using a different browser or running Firefox in a sandboxed environment until the patch is applied.
  • If an immediate update is not possible, consider using a different email client or running Thunderbird in a sandboxed environment until the patch is applied.

Generated by OpenCVE AI on August 21, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Fri, 21 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

Thu, 20 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
Weaknesses CWE-416
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla thunderbird
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 18 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Use-after-free in the Graphics: Text component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-21T20:12:37.811Z

Reserved: 2026-08-17T11:57:37.997Z

Link: CVE-2026-74940

cve-icon Vulnrichment

Updated: 2026-08-21T20:12:26.068Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T13:17:30.370

Modified: 2026-08-21T21:17:05.457

Link: CVE-2026-74940

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T12:23:28Z

Links: CVE-2026-74940 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:30:04Z

Weaknesses