CVE-2026-2447Patch(mozilla / firefox)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 17 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 14 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 9 mentions (2026-02-17); latest day: 1
  • 17 total mentions across 5 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline17 mentions / 5d
02579Mentions · 2026-02-16: 2Mentions · 2026-02-17: 9Mentions · 2026-02-19: 3Mentions · 2026-02-25: 2Mentions · 2026-06-12: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 7Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-06-12: 1Technical Details · 2026-02-16: 2Technical Details · 2026-02-17: 8Technical Details · 2026-02-19: 2Technical Details · 2026-02-25: 202-1602-1702-1902-2506-12
Signal classification3 categories
Patch
1376.5%
Disclosure
211.8%
General
211.8%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-162
Disclosure1Patch1
2026-02-179
Disclosure1General1Patch7
2026-02-193
General1Patch2
2026-02-252
Patch2
2026-06-121
Patch1
Full discourse17 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-2447)[2014390]Heap-BoF in libvpx(vp9) https://hg-edge.mozilla.org/mozilla-central/rev/02762b119a2bf869fb29b5003def3097e4103302 https://www.mozilla.org/en-US/security/advisories/mfsa2026-10/#CVE-2026-2447 Reported by jayjayjazz

    Post summary

    CVE‑2026‑2447 describes a heap buffer overflow in libvpx(vp9); the text references a Mozilla revision and advisory, providing disclosure details but no PoC, exploit, or patch information.

    01026191.8K
    4.8K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Mozilla ❗ CVE-2026-2447 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-mozilla-2/ https://t.co/53A9Av9yqu

    Post summary

    The tweet merely announces a CVE (CVE-2026-2447) affecting Mozilla products and provides a link for more information, with no other details provided.

    00011130
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2447 Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, and Firefox ESR < 115.32.1. https://www.cve.org/CVERecord?id=CVE-2026-2447

    Post summary

    The text announces CVE-2026-2447, noting a heap buffer overflow in libvpx affecting certain Firefox versions, but provides no PoC, exploit, or patch details.

    10001464
    56.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Mozilla Firefox の脆弱性 CVE-2026-2447 が FIX:動画処理を介して任意のコード実行 https://iototsecnews.jp/2026/02/17/firefox-v147-0-3-released-with-critical-fix-for-heap-buffer-overflow-vulnerability/ 脆弱性 CVE-2026-2447 (High) の原因は、Firefox が使用する libvpx におけるヒープバッファ・オーバーフローの欠陥にあります。VP8/VP9 動画処理中に、割り当てられたメモリ領域を超えて書き込みが行われる設計上の欠陥がありました。その結果として、細工された動画コンテンツや Web サイトを介した、任意のコード実行やブラウザ・クラッシュが発生する可能性があります。影響は Firefox 147.0.4 未満および Firefox ESR 140.7.1/115.32.1 未満に及び、修正版である 147.0.4/140.7.1/115.32.1 で対処されています。ご利用のユーザーは、ご注意ください。 #CVE20262447 #Firefox #Mozilla #Thunderbird #Vulnerability

    Post summary

    CVE-2026-2447 is a heap buffer overflow in Firefox’s libvpx that can enable arbitrary code execution via crafted video content; Mozilla has released a patch in Firefox 147.0.4 and ESR 140.7.1/115.32.1.

    01000172
    485 followersView on X
  • 【學】@manabu2111
    Patch

    定番の無料メールソフト「Thunderbird」に1件の脆弱性 ~修正版のv147.0.2が公開 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2086527.html 、修正された脆弱性は、VP8/VP9フォーマットのメディアを扱うオープンソースライブラリ「libvpx」で発見されたヒープバッファーオーバーフローの欠陥(CVE-2026-2447)、(続く)

    Post summary

    Mozilla Thunderbird released version 147.0.2 to patch a heap buffer overflow in the libvpx library (CVE‑2026‑2447) that affects VP8/VP9 media handling.

    1000058
    2.2K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Oracle released new Firefox 140.8.0 ESR and 140.9.0 ESR builds for Oracle Linux 7 addressing 39 CVEs, including CVE-2026-2447 and CVE-2026-4684, according to advisory ELSA-2026. https://threatcluster.io/cluster/oracle-linux-7-firefox-security-updates-address-multiple-cve-b8b9b55f

    Post summary

    Oracle has issued patched Firefox ESR builds for Linux 7 that fix 39 CVEs, including CVE‑2026‑2447 and CVE‑2026‑4684, but the text doesn’t detail the vulnerabilities or provide exploit information.

    00000111
    330 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Zero-Click Risk: SUSE Releases Emergency Firefox Patch for CVE-2026-2447 For enterprise IT teams: A critical vulnerability (CVSS 9.2) in the libvpx codec affects multiple SUSE Linux Enterprise products, including SAP applications. Read more: 👉 https://tinyurl.com/mr3atuyu #Security https://t.co/Oz8qEozp6M

    Post summary

    SUSE has issued an emergency patch for CVE‑2026‑2447, a critical libvpx codec vulnerability (CVSS 9.2) affecting SUSE Linux Enterprise products.

    0000052
    1.3K followersView on X
  • J. Canfield@CreativeBoulder
    Patch

    "@Mozilla Firefox Issues Emergency Patch for Heap Buffer Overflow in @Firefox v147" #linux #webdev https://thecyberexpress.com/firefox-v147-cve-2026-2447/

    Post summary

    Mozilla released an emergency patch for CVE‑2026‑2447, a heap buffer overflow affecting Firefox v147.

    0000027
    4.4K followersView on X
  • Cyber Daily News@CyberDaily_News
    Patch

    Firefox 147.0.4 patches CVE‑2026‑2447, a heap overflow in libvpx that lets malicious video trigger RCE. Patch fast (ESR) and sandbox media decoding to limit blast radius. https://thecyberexpress.com/firefox-v147-cve-2026-2447/ #infosec #CVE20262447 #Firefox

    Post summary

    Firefox 147.0.4 releases a patch for CVE‑2026‑2447, a heap overflow in libvpx that could lead to remote code execution, and applies sandboxing to limit the blast radius.

    0000049
    11 followersView on X
  • Alborz Safe@EthicalSafe
    Patch

    آسیب پذیری جدیدی با کد شناسایی CVE-2026-2447 و از نوع Buffer Overflow برای مرورگر های فایرفاکس نسخه های قبل از 147.0.4 منتشر شده است. منشا اصلی این آسیب پذیری ، library و کتابخانه ای به نام libvpx می باشد. برای امن سازی به نسخه 147.0.4 به روز رسانی نمایید. https://t.co/GoVA36ZBxa

    Post summary

    CVE-2026-2447 is a buffer overflow in Firefox’s libvpx library affecting versions prior to 147.0.4; users are advised to update to the patched release.

    0000062
    3 followersView on X
  • WindowsForum@windowsforum
    Patch

    🛠️ Firefox 147.0.4 fixes a blank New Tab and patches a cryptic libvpx bug—smooth tabs, safer streams. Upgrading keeps you in the loop without the jitters. #Firefox #TechNews #WindowsForum https://windowsforum.com/threads/firefox-147-0-4-fixes-blank-new-tab-and-libvpx-cve-2026-2447-patch.401483/?utm_source=rss&utm_medium=rss

    Post summary

    The post highlights the release of Firefox 147.0.4, which patches a libvpx bug (CVE‑2026‑2447), and advises users to upgrade for safety.

    0000051
    991 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Firefox 147.0.3 Security Update: Critical libvpx Heap Overflow (CVE-2026-2447) Patched Mozilla released Firefox 147.0.3 to address a high-severity heap buffer overflow in the libvpx VP8/VP9 video codec path (CVE-2026-2447) that could be triggered by crafted media to cause memory corruption and potential remote code execution. Upgrade to the fixed releases (Firefox 147.0.4 and ESR updates) to reduce exposure to drive-by exploitation via malicious web content. 🎯 Target: Global/Browser Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/mozilla-firefox-v147-0-3-released/

    Post summary

    Mozilla released Firefox 147.0.3 to patch a critical libvpx heap overflow (CVE‑2026‑2447), advising users to upgrade to mitigate potential remote code execution from crafted media.

    0000059
    176 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Firefox v147.0.3 Emergency Update: Heap Buffer Overflow (CVE-2026-2447) Could Enable RCE Mozilla patched a high-impact heap buffer overflow in Firefox’s libvpx (VP8/VP9) media processing path that could be triggered by visiting a malicious site with crafted video, potentially leading to memory corruption and remote code execution. Users should update immediately (patched builds include Firefox 147.0.4 and ESR updates) to reduce exposure to real-world exploitation attempts. 🎯 Target: Global/Browser Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/firefox-v147-0-3-released/

    Post summary

    Mozilla released an emergency update for Firefox 147.0.3 to address a high‑impact heap buffer overflow that could lead to remote code execution. Users are urged to update to patched builds to mitigate potential exploitation.

    0000052
    176 followersView on X
  • 趣テクノロジー@omomuki_tech
    Patch

    Mozilla Firefoxの最新バージョン147.0.4(ESR版は140.7.1および115.32.1)がリリースされました。 このアップデートは、「ヒープバッファオーバーフロー」と呼ばれる深刻な脆弱性(CVE-2026-2447)を修正するものです。 この問題は、ブラウザがVP8およびVP9形式の動画を処理するために使用する「libvpx」というビデオコーデックライブラリに存在していました。 ヒープバッファオーバーフローとは、プログラムがデータを書き込む際に、確保されたメモリ領域をはみ出してデータを書き込んでしまう問題です。 攻撃者は、この脆弱性を悪用して特別に細工した動画コンテンツやWebページを用意し、ユーザーがそれを開くだけで、隣接するメモリ領域に不正なコードを上書きさせることが可能でした。 これにより、最悪の場合、攻撃者がユーザーのコンピューター上で任意のコードを実行したり、ブラウザをクラッシュさせたり、システムを完全に制御したりする危険性がありました。 この脆弱性はMozillaによって影響度が「高」に分類されており、Windows、macOS、Linuxを含むすべてのデスクトップ版ユーザーが影響を受けます。 利用者の皆様は、Firefoxのメニューから「Firefoxについて」を開くことで、速やかにアップデートの確認と適用ができますので、早めの対応をおすすめします。 #Firefox #セキュリティ #脆弱性 https://cybersecuritynews.com/firefox-v147-0-3-released/

    Post summary

    Mozilla released Firefox 147.0.4 (ESR 140.7.1/115.32.1) to patch CVE-2026-2447, a heap buffer overflow in libvpx, with clear update instructions and no reported active exploitation or PoC.

    0000072
    215 followersView on X
  • haeretics@略称ヘレ@haeretics
    Patch

    修正されたのはヒープバッファーオーバーフローの欠陥(CVE-2026-2447)

    Post summary

    The statement indicates that CVE-2026-2447, a heap buffer overflow vulnerability, has been fixed, implying a patch is available.

    0000048
    475 followersView on X
  • 【學】@manabu2111
    General

    ヒープバッファーオーバーフローの欠陥(CVE-2026-2447)の1件、深刻度は4段階中上から2番目の「High」と評価されている

    Post summary

    The text reports a single high‑severity heap buffer overflow vulnerability (CVE‑2026‑2447) with no further details.

    0000040
    2.2K followersView on X
  • Lewis Lu@theLewisLu
    Patch

    @CVEnew Heap overflow in libvpx (CVE-2026-2447) is nasty—patch ASAP if you're on Firefox <147.0.4 / ESR <140.7.1 / <115.32.1.

    Post summary

    The post alerts users to a heap overflow CVE‑2026‑2447 in libvpx affecting Firefox and stresses the urgency of patching older versions.

    0000076
    389 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---

Explore more