CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4720

Critical · CVSS 9.8

Mozilla Firefox / Firefox ESR / Thunderbird — Memory safety bugs / Buffer overflow leading to arbitrary code execution (CWE-120)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-120, CWE-120

Description

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Search profile — drives PoC discovery

Symbols bug_id=2004652bug_id=2019372bug_id=2021922bug_id=2022567bug_id=2022733mfsa2026-20mfsa2026-22mfsa2026-23mfsa2026-24
Keywords CVE-2026-4720Firefox 148 memory corruptionFirefox ESR 140.8 memory safetyThunderbird 148 memory corruptionThunderbird ESR 140.8 buffer overflowMozilla memory safety bugs 2026Firefox 149 fix memory corruptionFirefox ESR 140.9 patchmfsa2026-20 PoCmfsa2026-22 PoCmfsa2026-23 PoCmfsa2026-24 PoCCWE-120 Firefox 2026
Versions: Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, Thunderbird ESR < 140.9

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z