Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196743 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-74940PATCHED
mozilla · firefox

Use-after-free in the Graphics: Text component

Description

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Affected Products

VendorProductVersions
mozillafirefox—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mozillafirefox esrcert_advisory90%
mozillathunderbirdcert_advisory90%
mozillafirefoxcert_advisory90%

References

  • https://bugzilla.mozilla.org/show_bug.cgi?id=2054842
  • https://www.mozilla.org/security/advisories/mfsa2026-74/
  • https://www.mozilla.org/security/advisories/mfsa2026-75/
  • https://www.mozilla.org/security/advisories/mfsa2026-76/
  • https://www.mozilla.org/security/advisories/mfsa2026-77/
  • https://www.mozilla.org/security/advisories/mfsa2026-78/
  • https://www.mozilla.org/security/advisories/mfsa2026-79/
  • https://www.mozilla.org/security/advisories/mfsa2026-80/

Related News (3 articles)

Tier B
BSI Advisories5d ago
[NEU] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR6d ago
Multiples vulnérabilités dans les produits Mozilla (19 août 2026)
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-74940 | Mozilla Firefox prior 115.39/140.14/153.1/154 Text use after free
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
115.39140.14153.1154
PublishedAug 18, 2026
Trending Score32
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-74989EXP
Internally found bugs fixed in Firefox 154
Trending: 34
CRITICALCVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Trending: 32
CRITICALCVE-2026-74961
Side-channel in the Web Audio component
Trending: 32
CRITICALCVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Trending: 32
CRITICALCVE-2026-74956
Same-origin policy bypass in the DOM: Service Workers component
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026
Patch Available
Aug 21, 2026