
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4721 is a memory safety vulnerability affecting Mozilla Firefox, Firefox ESR, and Thunderbird, involving multiple memory corruption bugs including classic buffer overflows (CWE-120) and expired pointer dereferences (CWE-825). The vulnerability was discovered by Christian Holler, Timothy Nikkel, and Tom Schuster of the Mozilla Fuzzing Team and publicly disclosed on March 24, 2026. Affected versions include Firefox ESR below 115.34, Firefox ESR below 140.9 (from 128.0), Firefox below 149, Thunderbird ESR below 140.9, and Thunderbird below 149. It carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory mfsa2026-21, Mozilla Advisory mfsa2026-22).
The vulnerability stems from multiple memory safety bugs present across Firefox and Thunderbird codebases, classified under CWE-120 (Buffer Copy without Checking Size of Input) and CWE-825 (Expired Pointer Dereference). Some of the identified bugs showed evidence of memory corruption, and Mozilla assessed that with sufficient effort, these could be exploited to achieve arbitrary code execution. The attack vector is network-based, requires no privileges and no user interaction, making it exploitable remotely without preconditions. The bugs were identified across multiple bug IDs (including 2013762, 2015291, 2016591, 2016661, 2016664, 2017303, 2017894, 2018090, 2018196, 2018379, 2019112, 2022090, 2022243, 2022351, 2022478, and 2022676) and were found through Mozilla's internal fuzzing efforts (Mozilla Advisory mfsa2026-20, Mozilla Advisory mfsa2026-21).
Successful exploitation of CVE-2026-4721 could allow a remote, unauthenticated attacker to execute arbitrary code on systems running vulnerable versions of Firefox, Firefox ESR, or Thunderbird, resulting in complete compromise of confidentiality, integrity, and availability. An attacker who achieves code execution in the browser context could access sensitive user data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The broad deployment of Firefox and Thunderbird across enterprise and consumer environments significantly amplifies the potential scope of impact (Mozilla Advisory mfsa2026-21, Mozilla Advisory mfsa2026-22).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-4721. The EPSS score is approximately 0.008% (0.000080), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
Mozilla has released patched versions addressing CVE-2026-4721: Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9. Users and administrators should update to these versions immediately. No configuration-based workarounds are available; upgrading is the only effective remediation. Enterprise administrators should prioritize patching given the critical CVSS score and the network-accessible, no-interaction-required attack vector. Linux distribution vendors including Red Hat, Debian, openSUSE, AlmaLinux, Rocky Linux, and Amazon Linux have also released updated packages (Mozilla Advisory mfsa2026-20, Mozilla Advisory mfsa2026-21, Mozilla Advisory mfsa2026-22).
Mozilla's release of Firefox 149 addressing 37 vulnerabilities, including CVE-2026-4721, received coverage from security-focused outlets such as CyberSecurityNews and HealSecurity, which highlighted the breadth of the patch batch and the critical nature of the memory safety fixes. Multiple Linux distribution vendors (Red Hat, Debian, openSUSE, AlmaLinux, Rocky Linux, Amazon Linux) promptly issued downstream security advisories and updated packages, reflecting the broad ecosystem impact. No notable individual researcher commentary or significant social media controversy has been identified beyond standard patch notification coverage.
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.9.0esr-1~deb12u1
sid
thunderbird: 1:140.9.0esr-1
trixie
thunderbird: 1:140.9.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."