
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5735 is a memory safety vulnerability affecting Mozilla Firefox and Thunderbird, involving memory corruption bugs (including out-of-bounds reads and writes) that could potentially be exploited to achieve arbitrary code execution. It affects Firefox versions prior to 149.0.2 and Thunderbird versions prior to 149.0.2, with the bugs specifically present in Firefox 149.0.1 and Thunderbird 149.0.1. The vulnerability was disclosed on April 7, 2026, and was reported by Brian Grinstead, Christian Holler, and the Mozilla Fuzzing Team. It carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory, GitHub Advisory).
The vulnerability is rooted in memory safety bugs classified under CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read), present in the Firefox and Thunderbird browser engines. These bugs showed evidence of memory corruption, and Mozilla assessed that with sufficient effort they could be exploited to run arbitrary code. The attack vector is network-based, requires no privileges and no user interaction, and the specific bugs are tracked in Mozilla's Bugzilla under bug IDs 2025475 and 2025477. For Thunderbird specifically, Mozilla notes that these flaws generally cannot be exploited through email because scripting is disabled when reading mail, but they represent risks in browser or browser-like contexts (Mozilla Advisory, Mozilla Advisory, GitHub Advisory).
Successful exploitation of CVE-2026-5735 could allow a remote, unauthenticated attacker to execute arbitrary code on the affected system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could leverage this to install malware, exfiltrate sensitive data, or use the compromised browser process as a foothold for lateral movement within a network. All users running Firefox or Thunderbird versions below 149.0.2 are at risk (Mozilla Advisory, GitHub Advisory).
Mozilla has released patched versions addressing this vulnerability: users should update Firefox to version 149.0.2 or later and Thunderbird to version 149.0.2 or later immediately. No configuration-based workarounds are available; upgrading is the only remediation. Organizations should enable automatic updates where possible to ensure timely deployment of security patches (Mozilla Advisory, Mozilla Advisory).
The CIS Security advisory noted that multiple vulnerabilities in Mozilla products, including CVE-2026-5735, could allow for arbitrary code execution, recommending prompt patching. OpenSUSE and other Linux distributions issued security announcements to push updated Firefox packages to their users. Community discussion on platforms such as Mastodon (infosec.exchange) and security-focused forums acknowledged the high CVSS score but noted the absence of active exploitation. Overall, the security community treated this as a routine but high-priority browser update (CIS Advisory, OpenSUSE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."