Junglewise Threat Intelligence

CVE-2026-4720: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-4720 · Severity: critical · CVSS 9.8 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browser and email applications used for internet browsing and communication. Multiple memory safety vulnerabilities were discovered that could allow an attacker to potentially take control of a user's computer or execute unauthorized commands. This could lead to the theft of sensitive personal data, unauthorized access to accounts, or the installation of malicious software.

Technical details

Mozilla Firefox and Thunderbird are vulnerable to multiple memory safety bugs (including buffer overflows) that exhibit evidence of memory corruption. These vulnerabilities exist in Firefox versions prior to 149, Firefox ESR versions prior to 140.9, Thunderbird versions prior to 149, and Thunderbird ESR versions prior to 140.9. An attacker could potentially exploit these flaws via the network to achieve arbitrary code execution in the context of the application. The root cause is identified as classic buffer overflows (CWE-120) and other memory management errors discovered through fuzzing. Patches are available in the latest releases of Firefox and Thunderbird.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 140.9
  • Mozilla Thunderbird < 149
  • Mozilla Thunderbird ESR < 140.9

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched

References

Related threats