
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2785 is an invalid pointer vulnerability in the JavaScript Engine component of Mozilla Firefox and Thunderbird. It was discovered and disclosed on February 24, 2026, affecting Firefox versions prior to 148, Firefox ESR versions prior to 140.8, Thunderbird versions prior to 148, and Thunderbird ESR versions prior to 140.8. Mozilla rated the vulnerability as moderate impact in its advisories, though Feedly's CVSS v3.1 assessment assigns a base score of 9.8 (Critical) (Mozilla Advisory mfsa2026-13, Mozilla Advisory mfsa2026-15). The vulnerability was reported by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger, using Claude from Anthropic (Mozilla Advisory mfsa2026-13).
The vulnerability is classified as CWE-824 (Access of Uninitialized Pointer), arising from improper handling of pointer state within Firefox's JavaScript Engine component (tracked internally as Bug 2013549). An attacker can trigger the invalid pointer condition through crafted JavaScript content delivered via a network-accessible attack vector, requiring no authentication and no user interaction beyond visiting a malicious page or opening a malicious email in Thunderbird. The bug was identified as part of a broader AI-assisted security research effort using Anthropic's Claude model, which uncovered multiple memory safety issues in the same release cycle (Mozilla Advisory mfsa2026-13, Mozilla Advisory mfsa2026-15).
Exploitation of this vulnerability could allow an attacker to achieve arbitrary code execution within the context of the browser or email client process, with potential high impact on confidentiality, integrity, and availability of the affected system. Because the flaw resides in the JavaScript Engine and requires no user interaction beyond loading attacker-controlled content, it poses a risk to any user running an unpatched version of Firefox or Thunderbird. Successful exploitation could lead to data theft, unauthorized system modifications, or service disruption, and may serve as a stepping stone for further lateral movement if the browser process has access to sensitive local resources (Mozilla Advisory mfsa2026-13, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a currently low probability of exploitation in the near term. No specific threat actor attribution has been reported in connection with this CVE.
Mozilla has released patches addressing CVE-2026-2785 in the following versions: Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird ESR 140.8. Organizations should prioritize upgrading to these versions or later immediately, particularly given the network-accessible, no-user-interaction attack vector. No configuration-based workarounds have been published; patching is the only recommended remediation. Downstream Linux distributions (Red Hat, Debian, SUSE, Rocky Linux, AlmaLinux, Oracle Linux, Amazon Linux) have also released updated packages (Mozilla Advisory mfsa2026-13, Mozilla Advisory mfsa2026-15).
The vulnerability was notable for being discovered through an AI-assisted security research process, with the reporters crediting Anthropic's Claude model as part of their methodology — a detail that attracted commentary in the security community regarding the growing role of AI in vulnerability research (VulnCheck Blog). Red Hat, Debian, SUSE, Rocky Linux, AlmaLinux, Oracle Linux, and Amazon Linux all issued downstream advisories and updated packages shortly after Mozilla's disclosure, reflecting broad ecosystem response. No significant social media controversy or unusual community sentiment was observed beyond general awareness of the AI-assisted discovery angle.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."