Junglewise Threat Intelligence

CVE-2026-8094: Mozilla Firefox and Thunderbird code injection in WebRTC

CVE-2026-8094 · Severity: critical · CVSS 9.8 · Published 2026-05-07

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Red Hat Enterprise Linux, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A critical security vulnerability has been identified in the WebRTC component of Mozilla Firefox and Thunderbird, which are widely used for web browsing and email communication. This flaw could allow a remote attacker to execute unauthorized code or gain control over an affected system. While Thunderbird users are generally protected when reading standard emails, the risk remains high in browser-like contexts or if malicious scripts are executed.

Technical details

This vulnerability is classified as a code injection issue (CWE-94) within the WebRTC component of Mozilla products. The flaw allows for improper control of code generation, which can be leveraged by a remote, unauthenticated attacker to execute arbitrary code on the target system. The attack vector is network-based and, according to CISA-ADP, does not require user interaction or elevated privileges, resulting in a CVSS score of 9.8. Mozilla has addressed this in Firefox ESR 140.10.2 and Thunderbird 140.10.2. Red Hat has also released corresponding updates for various Enterprise Linux versions.

Affected products

  • Mozilla Firefox ESR < 140.10.2
  • Mozilla Thunderbird < 140.10.2
  • Red Hat Enterprise Linux 8, 9, 10

Timeline

  • 2026-05-07: advisory: Mozilla Foundation Security Advisory 2026-41 published
  • 2026-05-07: patched: Fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2
  • 2026-05-19: advisory: Red Hat security advisory RHSA-2026:19160 published

References

Related threats