CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-100756, CVE-2026-100757, CVE-2026-100758 +59 more CVEs: firefox from 115.0 (inclusive), before 115.42.0 (exclusive), from 140.0.0 (inclusive), before…

CVE-2026-100756, CVE-2026-100757, CVE-2026-100758, CVE-2026-100759, CVE-2026-100760, CVE-2026-100762, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-100791, CVE-2026-100792, CVE-2026-100794, CVE-2026-100797, CVE-2

CVE-2026-100756

Affected technology

firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100757

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100758

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100759

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100760

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100762

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100765

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100766

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100767

Affected technology

firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100769

Affected technology

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100770

Affected technology

firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100771

Affected technology

firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100772

Affected technology

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100773

Affected technology

firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100774

Affected technology

firefox · from 115.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100775

Affected technology

firefox · from 115.0.1 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100776

Affected technology

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100777

Affected technology

firefox · from 115.0.1 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100778

Affected technology

firefox · from 115.0.1 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100779

Affected technology

firefox · before 157.0.0 (exclusive)
mozilla

firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · before 157.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100780

Affected technology

firefox · before 157.0.0 (exclusive)
mozilla

firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · before 157.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100781

Affected technology

firefox · before 157.0.0 (exclusive)
mozilla

firefox · from 115.1.0 (inclusive), before 115.42.0 (exclusive)
mozilla

firefox · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · before 157.0 (exclusive)
mozilla

thunderbird · from 140.0 (inclusive), before 140.17.0 (exclusive)
mozilla

thunderbird · from 153.0 (inclusive), before 153.4.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100782

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100783

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100784

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100785

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100786

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100787

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100788

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100789

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100790

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100791

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100792

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as high; integrity impact as low; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100794

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100797

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100798

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100800

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100801

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100803

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100806

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100807

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100808

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100809

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100811

Affected technology

firefox · before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100812

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 6.5/10) rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100814

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100815

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100816

Affected technology

firefox · before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100818

Affected technology

firefox · before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100819

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 9.6/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100820

Affected technology

firefox · before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100821

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100822

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and availability impact as low; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100824

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100825

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100826

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100828

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100829

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100830

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality and integrity impact as high; availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100831

Affected technology

Product not specified by the source · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (OSV, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

OSV’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-100832

Affected technology

firefox · before 115.42.0 (exclusive)
mozilla

firefox · from 116.0 (inclusive), before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

CVE-2026-96869

Affected technology

firefox · before 140.17.0 (exclusive)
mozilla

firefox · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

firefox · from 154.0.0 (inclusive), before 157.0.0 (exclusive)
mozilla

thunderbird · before 140.17.0 (exclusive)
mozilla

thunderbird · from 141.0 (inclusive), before 153.4.0 (exclusive)
mozilla

thunderbird · from 154.0 (inclusive), before 157.0 (exclusive)
mozilla

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · User interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality impact as low; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CVE
CVE-2026-100759, CVE-2026-100760, CVE-2026-100762, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-100791, CVE-2026-100792, CVE-2026-100794, CVE-2026-100797, CVE-2026-100798, CVE-2026-100800, CVE-2026-100801, CVE-2026-100803, CVE-2026-100806, CVE-2026-100807, CVE-2026-100808, CVE-2026-100809, CVE-2026-100811, CVE-2026-100812, CVE-2026-100814, CVE-2026-100815, CVE-2026-100816, CVE-2026-100818, CVE-2026-100819, CVE-2026-100820, CVE-2026-100821, CVE-2026-100822, CVE-2026-100824, CVE-2026-100825, CVE-2026-100826, CVE-2026-100828, CVE-2026-100829, CVE-2026-100830, CVE-2026-100831, CVE-2026-100832, CVE-2026-96869
CWE
CWE-20, CWE-119, CWE-200, CWE-269, CWE-346, CWE-416, CWE-457, CWE-693, CWE-758, CWE-770
Product
MozillaFirefox
CCR priority
32.5 /100 (P4)
CVSS 3.1
8.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N · Source advisory
EPSS
0.00329 · percentile 0.23728 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-100756.html