CVE-2026-4727
7.5Mozilla · Firefox, Thunderbird
A denial of service vulnerability exists within the NSS library component of Mozilla Firefox and Thunderbird, allowing an unauthenticated attacker to cause application instability.
Executive summary
A critical denial of service vulnerability in the NSS library of Mozilla Firefox and Thunderbird requires immediate updates to prevent service disruption.
Vulnerability
This vulnerability resides in the NSS (Network Security Services) component of the affected applications. The CVSS vector of AV:N/AC:L/PR:N/UI:N indicates that an unauthenticated remote attacker can trigger this denial of service condition without user interaction or specialized privileges.
Business impact
The ability for an unauthenticated attacker to remotely crash browser or email client processes poses a significant risk to business continuity and operational productivity. Given the CVSS score of 7.5, this high severity flaw could lead to widespread service unavailability for end-users, potentially disrupting critical workflows that rely on these applications for secure communication and web access.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor system logs and endpoint stability reports for unusual process terminations or recurring application crashes that may indicate active exploitation attempts.
Compensating Controls: While no specific WAF rule can mitigate this internal library flaw, ensure that host-based intrusion prevention systems are active to detect and block abnormal network traffic patterns directed at these applications.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this denial of service vulnerability necessitates a prompt organizational response. Administrators should prioritize the deployment of Firefox and Thunderbird version 149 across all managed endpoints to eliminate the risk of service disruption. Ensure that automated update mechanisms are functioning correctly to maintain continuous protection against this and future vulnerabilities.
More Mozilla CVEs
Sources
Originally found and disclosed by Cody, per the CVE Program record.