
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2764 is a JIT miscompilation and use-after-free vulnerability in the JavaScript Engine JIT component of Mozilla Firefox and Thunderbird. It was discovered by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic, and was publicly disclosed on February 24, 2026. Affected products include Firefox prior to 148, Firefox ESR prior to 115.33, Firefox ESR prior to 140.8, Thunderbird prior to 148, and Thunderbird ESR prior to 140.8. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory mfsa2026-13, Mozilla Advisory mfsa2026-15, Feedly).
The vulnerability is classified as CWE-416 (Use After Free) and stems from a JIT miscompilation flaw in Firefox's JavaScript engine JIT component, which can result in a use-after-free condition (Feedly). When the JIT compiler incorrectly compiles JavaScript code, it may generate machine code that accesses memory after it has been freed, allowing an attacker to potentially control the freed memory region and redirect execution flow. The vulnerability is exploitable remotely over the network with no privileges required and no user interaction needed, making it particularly severe. The underlying bug is tracked as Mozilla bug 2012608, though the bug report is access-restricted (Mozilla Advisory mfsa2026-13).
Successful exploitation of CVE-2026-2764 can result in arbitrary code execution on the affected system, with full impact to confidentiality, integrity, and availability. An attacker who delivers crafted JavaScript content to a vulnerable browser or email client instance — for example via a malicious webpage or HTML email — could achieve code execution in the context of the browser process. This could enable data theft, installation of malware, lateral movement within a network, or complete compromise of the affected endpoint (Feedly, Mozilla Advisory mfsa2026-13).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. The vulnerability was discovered through AI-assisted security research using Anthropic's Claude, which is a notable aspect of its discovery methodology (Mozilla Advisory mfsa2026-13, VulnCheck Blog).
cmd.exe, powershell.exe, /bin/sh, curl, wget) that are not typical browser subprocesses.Mozilla has released patched versions addressing CVE-2026-2764: Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird ESR 140.8. Organizations should immediately upgrade all affected installations to these versions or later. No configuration-based workaround is available; upgrading is the only effective remediation. Given the critical CVSS score and the potential for remote code execution without user interaction, patching should be treated as high priority (Mozilla Advisory mfsa2026-13, Mozilla Advisory mfsa2026-14, Mozilla Advisory mfsa2026-15).
The vulnerability was notably discovered using AI-assisted security research — specifically, the researchers used Anthropic's Claude to help identify the flaw, which drew attention from the security community as an example of AI-augmented vulnerability research (VulnCheck Blog). Multiple Linux distributions (Red Hat, Debian, SUSE, AlmaLinux, Rocky Linux, Oracle Linux, Slackware, Amazon Linux) rapidly issued security advisories and updated packages following Mozilla's disclosure, reflecting the broad ecosystem impact of Firefox and Thunderbird vulnerabilities. The SOS Intelligence CVE Chatter Weekly Top Ten for the week of March 2, 2026 included this CVE, indicating notable community discussion (Feedly).
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.8.0esr-1~deb12u1
sid
thunderbird: 1:140.8.0esr-1
trixie
thunderbird: 1:140.8.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."