CVE-2026-74988
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or anoth
CVSS
9.8
Critical
EPSS
0.4%
p28
KEV
—
Exploit Today
9
0-100
Published: Aug 18, 2026 · Last modified: Sep 1, 2026 · CWE-119
0.2%EPSS · 30 days0.4%
2026-08-192026-09-15
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2018164%2C2045404%2C2045507%2C2045711%2C2052403%2C2053174%2C2054643%2C2054667%2C2054671%2C2054674%2C2054687%2C2054717%2C2054761%2C2054787%2C2055676%2C2056779%2C2056781%2C2058629%2C2059019%2C2059138
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2045796%2C2046734%2C2051424%2C2054721%2C2057994%2C2058094%2C2058611%2C2058615%2C2058616%2C2061315
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2053153%2C2053262%2C2054763%2C2059198%2C2059224
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-74/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-77/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-78/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-80/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-923997.3 HIG—
———A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.26 is able to mitigate this issue. This patch is called 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12. Upgrading the affected component is recommended.3hCVE-2026-921787.8 HIG—
———pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28916.16hCVE-2026-198867.8 HIG—
———OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of OGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29340.16hCVE-2026-920548.8 HIG—
——0Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.5hCVE-2026-910914.3 MED32.7%
——10A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.1dCVE-2026-910903.9 LOW2.4%
——1A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is sufficient to fix this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. The affected component should be upgraded.1d