CVE-2026-4726
7.5Mozilla · Firefox, Thunderbird
A denial of service vulnerability exists in the XML component of Mozilla Firefox and Thunderbird, allowing unauthenticated attackers to cause a crash.
Executive summary
An unauthenticated remote denial of service vulnerability in Mozilla Firefox and Thunderbird poses a risk to service availability.
Vulnerability
The vulnerability resides in the XML processing component of the software. An unauthenticated attacker can trigger a denial of service condition by supplying specially crafted XML data, resulting in a crash of the application.
Business impact
Successful exploitation of this flaw leads to service disruption, as the application process will terminate unexpectedly when the malicious XML is processed. With a CVSS score of 7.5, this high severity vulnerability represents a significant risk to operational continuity, particularly for users relying on these applications for critical communication or web-based workflows.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or later to incorporate the vendor-supplied fix.
Proactive Monitoring: Review application logs for recurring crash events or unusual XML processing errors that may indicate an attempt to trigger this vulnerability.
Compensating Controls: While no direct virtual patch exists, maintaining updated antivirus and endpoint protection solutions may help detect or block known malicious exploit payloads targeting XML components.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high impact on service availability and the ease with which this vulnerability can be triggered, organizations should prioritize updating all instances of Mozilla Firefox and Thunderbird. Administrators must ensure that the update to version 149 is deployed across the enterprise to mitigate the risk of denial of service attacks.
More Mozilla CVEs
Sources
Originally found and disclosed by Hanno Boeck, per the CVE Program record.