CVE-2026-74966CWE-359
CVE-2026-74966
High · published August 18, 2026
What it is
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00256 · 17.1th percentile
- Weakness
- CWE-359 · Exposure of Private Personal Information to an Unauthorized Actor
- Published
- 2026-08-18T17:17Z
Affected products (2)
| Product | Versions | Fixed in |
|---|
| mozilla/firefox | < 153.1.0 | 153.1.0 |
| mozilla/thunderbird | < 153.1.0 | 153.1.0 |
References (5)
EPSS history
Timeline