CVE-2026-6765
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- Affected products
- Firefox, Red Os, Rocky Linux, Thunderbird
- Mozilla Firefox
- < 140.10.0, 150.0
- Mozilla Thunderbird
- < 140.10.0
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.2% (12th percentile)
- Weakness
- CWE-359
- NVD status
- Analyzed
- Published
- 2026-04-21
CVE-2026-6765 at NVD
1 known exploit for CVE-2026-6765
Proof-of-concept code and exploit modules indexed by Sploitus