CVE-2026-2793
Critical · CVSS 9.8Mozilla Firefox / Thunderbird — Memory safety bugs / out-of-bounds write (OOB write) leading to arbitrary code execution
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-787, CWE-787
Description
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
Search profile — drives PoC discovery
Symbols CVE-2026-2793mfsa2026-13mfsa2026-14mfsa2026-15mfsa2026-16bug_id=2015196bug_id=2016423bug_id=2016498CWE-787
Keywords CVE-2026-2793Firefox memory corruptionFirefox 147 OOB writeFirefox ESR 115.32 memory safetyFirefox ESR 140.7 memory safetyThunderbird 147 memory corruptionmfsa2026-13mfsa2026-14mfsa2026-15mfsa2026-16Firefox 148 patchMozilla memory safety bugs 2026Firefox arbitrary code execution 2026bugzilla 2015196bugzilla 2016423bugzilla 2016498
Versions: Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, Thunderbird ESR < 140.8
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2015196%2C2016423%2C2016498
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338
- https://access.redhat.com/errata/RHSA-2026:3339
- https://access.redhat.com/errata/RHSA-2026:3361
- https://access.redhat.com/errata/RHSA-2026:3491
- https://access.redhat.com/errata/RHSA-2026:3492
- https://access.redhat.com/errata/RHSA-2026:3493
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z