Junglewise Threat Intelligence

CVE-2026-2793: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-2793 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular open-source web browsers and email clients used globally for internet browsing and communication. Multiple memory safety vulnerabilities have been identified that could allow an attacker to corrupt the application's memory. In a worst-case scenario, this could enable an attacker to take control of a user's computer or execute unauthorized commands simply by tricking the user into visiting a malicious website or opening a specially crafted email.

Technical details

This advisory covers a collection of memory safety bugs (CWE-787) identified within the Mozilla codebase. These vulnerabilities manifest as memory corruption issues in various components of the browser and mail client. An attacker could potentially exploit these flaws via a remote network vector, such as a malicious website or email, without requiring special privileges. If successfully exploited, these bugs could allow for arbitrary code execution within the context of the application. The vulnerabilities have been addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 115.33, < 140.8
  • Mozilla web browser Thunderbird < 148
  • Mozilla Thunderbird ESR < 140.8

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: advisory
  • 2026-02-24: patched

References

Related threats