Input validation error in Mozilla Firefox and Firefox for Android - CVE-2026-6777
Published: April 21, 2026
Vulnerability identifier: #VU126691
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6777
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the Networking: DNS component. A remote attacker can bypass implemented security restrictions.
Affected software
Mozilla Firefox
Firefox for Android
Anolis OS
Mozilla Thunderbird
firefox
Firefox for Android
Anolis OS
Mozilla Thunderbird
firefox
How to mitigate CVE-2026-6777
Install updates from vendor's website.
Mozilla Firefox - update to 150.0
Firefox for Android - update to 150.0
Mozilla Thunderbird - update to 150.0
firefox - update to 140.10.0-1
Firefox for Android - update to 150.0
Mozilla Thunderbird - update to 150.0
firefox - update to 140.10.0-1