Junglewise Threat Intelligence

CVE-2026-4721: Mozilla Firefox and Thunderbird multiple memory safety bugs

CVE-2026-4721 · Severity: critical · CVSS 9.8 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are affected by multiple memory safety vulnerabilities that could allow an attacker to corrupt the application's memory. In practice, a successful exploit could allow an attacker to take control of the affected system or execute unauthorized commands. Users should update to the latest versions of these applications to protect their data and systems from potential compromise.

Technical details

Mozilla developers and community members reported multiple memory safety bugs across various versions of Firefox and Thunderbird. These vulnerabilities include issues such as buffer overflows (CWE-120) and expired pointer dereferences (CWE-825). An attacker could potentially exploit these flaws by tricking a user into visiting a malicious website or processing specially crafted content, leading to memory corruption. Mozilla presumes that with sufficient effort, some of these bugs could be leveraged to achieve arbitrary code execution. The issues are resolved in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Affected products

  • Mozilla Firefox ESR < 115.34
  • Mozilla Firefox ESR < 140.9
  • Mozilla Firefox < 149
  • Mozilla Thunderbird ESR < 140.9
  • Mozilla Thunderbird < 149

Timeline

  • 2026-03-24: advisory
  • 2026-03-24: patched

References

Related threats