CVE-2026-0891
8.1Mozilla · Firefox and Thunderbird
Multiple memory safety vulnerabilities in Mozilla Firefox and Thunderbird may allow for arbitrary code execution through memory corruption.
Executive summary
Several critical memory safety vulnerabilities in Mozilla Firefox and Thunderbird could allow an unauthenticated attacker to execute arbitrary code via memory corruption.
Vulnerability
This issue consists of multiple memory safety bugs that result in memory corruption within the application. These flaws can be triggered by an unauthenticated attacker, potentially leading to arbitrary code execution if the application processes specially crafted content.
Business impact
The ability for an attacker to achieve arbitrary code execution poses a severe risk to organizational security, potentially leading to full system compromise, data exfiltration, or the installation of persistent malware. Given the high CVSS score of 8.1, this vulnerability represents a significant threat to endpoint integrity. Organizations relying on these browsers and email clients must prioritize remediation to prevent unauthorized access to sensitive local data and corporate networks.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 147, or to the ESR 140.7 release, to apply the necessary security patches.
Proactive Monitoring: Monitor system logs for unusual process crashes or unexpected behavioral patterns in browser and mail client activity which may indicate exploitation attempts.
Compensating Controls: While no direct virtual patch exists, ensure that endpoint protection platforms are active and that users are restricted from executing untrusted files or navigating to suspicious web content.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
These vulnerabilities represent a high risk due to the potential for arbitrary code execution. Security teams should prioritize the deployment of the Mozilla 147 or ESR 140.7 updates across all managed endpoints immediately. Failure to patch these versions leaves systems susceptible to memory corruption attacks that could bypass standard security controls.
More Mozilla CVEs
Sources
Originally found and disclosed by Andrew McCreight, Dennis Jackson and the Mozilla Fuzzing Team, per the CVE Program record.