CVE-2026-84142
massMemory corruption bugs in Mozilla Firefox and Thunderbird (fixed in 155)
CVE-2026-84142 is a Mozilla advisory covering multiple internally discovered bugs in Thunderbird 154, some showing evidence of memory corruption (CWE-119) or other security-relevant defects, with possible information exposure (CWE-200). The flaws are network-reachable with no privileges or user interaction required per the CVSS vector, meaning an attacker could potentially trigger them through content processed by the browser or mail client, and with sufficient effort could have gained code execution or access to sensitive information. Users running Firefox or Thunderbird versions prior to 155 are affected. The issues were fixed in Firefox 155 and Thunderbird 155. There is no known public proof-of-concept, no CISA KEV listing, and only a low estimated exploitation probability (EPSS 0.3%), so no in-the-wild exploitation is currently known.
What to do: Upgrade Firefox to 155 and Thunderbird to 155, which are the fixed releases; verify installed versions rather than assuming auto-update has completed. No workarounds are described, but until patching, avoid opening untrusted web content or email attachments in affected builds. No in-the-wild exploitation is known, so this can be patched in normal cycles, though the critical CVSS score justifies prompt updates on endpoints handling untrusted content.
| mozilla firefox | versions prior to 155 |
| mozilla thunderbird | versions prior to 155 (bugs described in Thunderbird 154) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-119, CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.