CVE-2026-8946
Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- CVSS
- 7.5
- EPSS
- 0.45% 36.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.19