CVE-2026-4726

7.5

Mozilla · Firefox, Thunderbird

A denial of service vulnerability exists in the XML component of Mozilla Firefox and Thunderbird, allowing unauthenticated attackers to cause a crash.

Executive summary

An unauthenticated remote denial of service vulnerability in Mozilla Firefox and Thunderbird poses a risk to service availability.

Vulnerability

The vulnerability resides in the XML processing component of the software. An unauthenticated attacker can trigger a denial of service condition by supplying specially crafted XML data, resulting in a crash of the application.

Business impact

Successful exploitation of this flaw leads to service disruption, as the application process will terminate unexpectedly when the malicious XML is processed. With a CVSS score of 7.5, this high severity vulnerability represents a significant risk to operational continuity, particularly for users relying on these applications for critical communication or web-based workflows.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or later to incorporate the vendor-supplied fix.

Proactive Monitoring: Review application logs for recurring crash events or unusual XML processing errors that may indicate an attempt to trigger this vulnerability.

Compensating Controls: While no direct virtual patch exists, maintaining updated antivirus and endpoint protection solutions may help detect or block known malicious exploit payloads targeting XML components.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact on service availability and the ease with which this vulnerability can be triggered, organizations should prioritize updating all instances of Mozilla Firefox and Thunderbird. Administrators must ensure that the update to version 149 is deployed across the enterprise to mitigate the risk of denial of service attacks.

More Mozilla CVEs

Sources

Originally found and disclosed by Hanno Boeck, per the CVE Program record.