CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-2807

Critical · CVSS 9.8

Mozilla Firefox / Thunderbird — Memory corruption / Out-of-bounds write (CWE-787) leading to arbitrary code execution

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-787, CWE-787

Description

Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

Search profile — drives PoC discovery

Symbols mfsa2026-13mfsa2026-16bug_id=1756056bug_id=1999402bug_id=2004872bug_id=2006037bug_id=2012855CVE-2026-2807
Keywords CVE-2026-2807Firefox 147 memory corruptionThunderbird 147 memory corruptionFirefox 148 memory safetymfsa2026-13mfsa2026-16out-of-bounds write Firefoxmemory safety bugs Firefox 147arbitrary code execution Firefox 148Mozilla memory corruption PoC
Versions: Firefox <= 147, Thunderbird <= 147 (fixed in Firefox 148, Thunderbird 148)

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z