Vulnerability CVE-2026-2793: Information

Description

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Feb. 24, 2026
Modified: Feb. 25, 2026
Error type identifier: CWE-787

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus148.0-alt1148.0-alt2ALT-PU-2026-3542-2409187Fixed
firefoxsisyphus_loongarch64148.0-alt0.port148.0-alt0.portALT-PU-2026-3960-1-Fixed
firefoxp11148.0-alt2147.0.2-alt1ALT-PU-2026-4175-1409232Testing
firefox-esrsisyphus140.8.0-alt1140.8.0-alt1ALT-PU-2026-3923-2409748Fixed
thunderbirdsisyphus148.0-alt1148.0-alt2ALT-PU-2026-3544-2409185Fixed
thunderbirdsisyphus_riscv64148.0-alt1148.0-alt2ALT-PU-2026-3685-1-Fixed
thunderbirdsisyphus_loongarch64148.0-alt0.port148.0-alt0.portALT-PU-2026-4198-1-Fixed

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
      End excluding
      115.33.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
      End excluding
      148.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
      Start including
      128.0
      End excluding
      140.8.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
      End excluding
      140.8.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
      End excluding
      148.0