Junglewise Threat Intelligence

CVE-2026-2792: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-2792 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla has released security updates to address multiple memory safety vulnerabilities in the Firefox web browser and Thunderbird email client. These flaws could allow an attacker to potentially execute malicious code on a user's system if they visit a specially crafted website or interact with malicious content. While Thunderbird is generally less susceptible during normal email reading because scripting is disabled, the risk remains in browser-like contexts within the application.

Technical details

This advisory covers a collection of memory safety bugs (CVE-2026-2792) identified in Mozilla's core engine. The vulnerabilities include evidence of memory corruption which, through heap or stack manipulation, could be leveraged for arbitrary code execution. The attack vector is typically remote, triggered when the application processes malicious web content. In Thunderbird, the risk is mitigated during standard email viewing as JavaScript is disabled by default, but the vulnerabilities can be reached in other browser-like components of the suite. Mozilla has patched these issues by improving memory handling and boundary checks in the affected versions.

Affected products

  • Mozilla Firefox ESR 140.7
  • Mozilla Thunderbird ESR 140.7
  • Mozilla Firefox 147
  • Mozilla Thunderbird 147

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: patched
  • 2026-02-24: advisory

References

Related threats