CVE-2026-8092

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

18 May 2026, 08:16

Type Values Removed Values Added
Summary (en) Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2. (en) Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

11 May 2026, 15:16

Type Values Removed Values Added
First Time Mozilla thunderbird
Mozilla
Mozilla firefox
References () https://bugzilla.mozilla.org/buglist.cgi?bug_id=1806249%2C2021977%2C2022576%2C2022722%2C2024439%2C2027883%2C2029463%2C2030323%2C2032042%2C2032043%2C2033270%2C2033637%2C2034422%2C2034496%2C2035879%2C2036516 - () https://bugzilla.mozilla.org/buglist.cgi?bug_id=1806249%2C2021977%2C2022576%2C2022722%2C2024439%2C2027883%2C2029463%2C2030323%2C2032042%2C2032043%2C2033270%2C2033637%2C2034422%2C2034496%2C2035879%2C2036516 - Broken Link
References () https://www.mozilla.org/security/advisories/mfsa2026-40/ - () https://www.mozilla.org/security/advisories/mfsa2026-40/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-41/ - () https://www.mozilla.org/security/advisories/mfsa2026-41/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-42/ - () https://www.mozilla.org/security/advisories/mfsa2026-42/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-43/ - () https://www.mozilla.org/security/advisories/mfsa2026-43/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-44/ - () https://www.mozilla.org/security/advisories/mfsa2026-44/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

08 May 2026, 15:17

Type Values Removed Values Added
CWE CWE-125
CWE-416
CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

08 May 2026, 13:16

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-43/ -
  • () https://www.mozilla.org/security/advisories/mfsa2026-44/ -
Summary (en) Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, and Firefox ESR 115.35.2. (en) Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

07 May 2026, 14:08

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 13:16

Updated : 2026-05-18 08:16


NVD link : CVE-2026-8092

Mitre link : CVE-2026-8092

CVE.ORG link : CVE-2026-8092


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-125

Out-of-bounds Read

CWE-416

Use After Free

CWE-787

Out-of-bounds Write