CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-2792

Critical · CVSS 9.8

Firefox / Thunderbird — Memory corruption / out-of-bounds write (CWE-787) leading to arbitrary code execution

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-787, CWE-787

Description

Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Search profile — drives PoC discovery

Symbols mfsa2026-13mfsa2026-15mfsa2026-16mfsa2026-17bug_id=2008912bug_id=2010050bug_id=2010275bug_id=2012331
Keywords CVE-2026-2792Firefox 147Firefox ESR 140.7Thunderbird 147Thunderbird ESR 140.7memory safety bugsmemory corruptionFirefox 148 fixFirefox ESR 140.8mfsa2026CWE-787arbitrary code execution Firefox
Versions: Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, Thunderbird ESR < 140.8

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z