
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2766 is a use-after-free vulnerability in the JavaScript Engine's JIT (Just-In-Time) compiler component of Mozilla Firefox and Thunderbird. Disclosed on February 24, 2026, it affects Firefox versions prior to 148.0, Firefox ESR versions prior to 140.8.0, Thunderbird versions prior to 148.0, and Thunderbird ESR versions prior to 140.8.0. The vulnerability was discovered and reported by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic (Mozilla Advisory MFSA2026-13, Mozilla Advisory MFSA2026-15). It carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly).
The vulnerability is classified as CWE-416 (Use After Free) and resides in the JavaScript Engine's JIT compiler component of Firefox and Thunderbird (Mozilla Advisory MFSA2026-15). A use-after-free flaw occurs when the JIT compiler accesses memory that has already been freed, potentially allowing an attacker to control the freed memory region and redirect execution flow. The attack vector is network-based, requires no privileges, and no user interaction, making it exploitable by any remote attacker who can deliver malicious JavaScript content to a vulnerable browser or email client. The underlying bug is tracked as Mozilla Bug 2013583, though the bug report is access-restricted (Feedly).
Successful exploitation of CVE-2026-2766 can result in arbitrary code execution within the context of the affected browser or email client, with high impact to confidentiality, integrity, and availability (Feedly). An attacker could leverage this to read sensitive data from browser memory, modify application state, or achieve a persistent foothold on the victim's system. In enterprise environments, a compromised browser session could serve as an initial access vector for lateral movement across the network.
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.018% (0.000180), indicating a currently low probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Notably, the vulnerability was discovered using AI-assisted security research (Claude from Anthropic), which has been highlighted as a novel discovery methodology (VulnCheck Blog).
firefox, firefox-esr, or thunderbird executables (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget); browser processes consuming abnormally high memory or CPU consistent with heap manipulation.Mozilla has released patched versions addressing this vulnerability: Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird ESR 140.8 (Mozilla Advisory MFSA2026-13, Mozilla Advisory MFSA2026-15). Organizations should immediately update all Firefox and Thunderbird installations to the patched versions, prioritizing internet-facing and high-value systems. No configuration-based workaround is available; upgrading is the only effective remediation. Automated patch management tools should be used to ensure rapid deployment across enterprise environments.
The discovery of CVE-2026-2766 and related vulnerabilities in the same release batch attracted notable attention due to the use of Anthropic's Claude AI model as a research tool, with VulnCheck publishing a blog post specifically highlighting the AI-assisted CVE discovery methodology (VulnCheck Blog). The broader February 24, 2026 Mozilla security release — which included dozens of high-severity vulnerabilities — received widespread coverage from Linux security advisories, Red Hat, Debian, SUSE, Slackware, Rocky Linux, AlmaLinux, Oracle Linux, and Amazon Linux, reflecting the broad ecosystem impact of the Firefox/Thunderbird update cycle.
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.8.0esr-1~deb12u1
sid
thunderbird: 1:140.8.0esr-1
trixie
thunderbird: 1:140.8.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."