CVE-2026-74966CWE-359

CVE-2026-74966

High · published August 18, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
17.1
In the wild
Unconfirmed
What it is

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00256 · 17.1th percentile
Weakness
CWE-359 · Exposure of Private Personal Information to an Unauthorized Actor
Published
2026-08-18T17:17Z
Affected products (2)
ProductVersionsFixed in
mozilla/firefox< 153.1.0153.1.0
mozilla/thunderbird< 153.1.0153.1.0
References (5)
EPSS history
Timeline
  • 18 AUG 12:23Z
    Information disclosure in the Form Autofill component
    cvelistv5