CVE-2026-2793

CRITICAL

Firefox/Thunderbird ESR - Memory Corruption

Title source: llm

Description

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Scores

CVSS v3 9.8
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-787
Status published

Affected Products (4)

mozilla/firefox < 115.33.0
mozilla/firefox < 148.0
mozilla/thunderbird < 140.8.0
mozilla/thunderbird < 148.0

Timeline

Published Feb 24, 2026
Tracked Since Feb 24, 2026