Junglewise Threat Intelligence

CVE-2026-2807: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-2807 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are widely used web browsing and email applications. Multiple memory safety vulnerabilities were identified that could allow an attacker to potentially take control of a user's computer or execute unauthorized commands. These issues are typically triggered when the application processes specially crafted web content or malicious scripts.

Technical details

This advisory covers a collection of memory safety bugs (CWE-787) identified in Firefox and Thunderbird. The root cause involves various memory corruption issues that, while not individually detailed in the high-level advisory, collectively present a risk of arbitrary code execution. The attack vector is remote via the network, typically requiring a user to visit a malicious website or interact with malicious content that triggers the memory corruption. In Thunderbird, the risk is mitigated during standard email reading as scripting is disabled, but remains a threat in browser-like contexts. The vulnerabilities are resolved in Firefox 148 and Thunderbird 148.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Thunderbird < 148

Timeline

  • 2026-02-24: advisory: Mozilla Foundation Security Advisory published
  • 2026-02-24: patched: Fixed in Firefox 148 and Thunderbird 148

References

Related threats