CVE-2026-8093

Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

18 May 2026, 08:16

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.mozilla.org/buglist.cgi?bug_id=1981270%2C2027154%2C2028332%2C2029327%2C2029428%2C2029894%2C2032189%2C2034837%2C2035968%2C2036256', 'tags': ['Broken Link'], 'source': 'security@mozilla.org'}
  • () https://bugzilla.mozilla.org/buglist.cgi?bug_id=1981270%2C2027154%2C2028332%2C2029327%2C2029894%2C2032189%2C2034837%2C2035968%2C2036256 -
Summary (en) Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2. (en) Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.

11 May 2026, 15:12

Type Values Removed Values Added
First Time Mozilla thunderbird
Mozilla
Mozilla firefox
References () https://bugzilla.mozilla.org/buglist.cgi?bug_id=1981270%2C2027154%2C2028332%2C2029327%2C2029428%2C2029894%2C2032189%2C2034837%2C2035968%2C2036256 - () https://bugzilla.mozilla.org/buglist.cgi?bug_id=1981270%2C2027154%2C2028332%2C2029327%2C2029428%2C2029894%2C2032189%2C2034837%2C2035968%2C2036256 - Broken Link
References () https://www.mozilla.org/security/advisories/mfsa2026-40/ - () https://www.mozilla.org/security/advisories/mfsa2026-40/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-43/ - () https://www.mozilla.org/security/advisories/mfsa2026-43/ - Vendor Advisory
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

08 May 2026, 15:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 8.1

08 May 2026, 13:16

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-43/ -
Summary (en) Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2. (en) Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.

07 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 13:16

Updated : 2026-05-18 08:16


NVD link : CVE-2026-8093

Mitre link : CVE-2026-8093

CVE.ORG link : CVE-2026-8093


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer