VulnerabilityAnalyzed
CVE-2026-8961
This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
MEDIUM 6.5EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- mozilla/firefox · mozilla/thunderbird
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1962625Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2026-46/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-48/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-50/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-51/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.