CVE-2026-4721Disclosure(mozilla / firefox)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120CWE-825

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-24: 2Mentions · 2026-06-30: 1Active Exploitation · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-03-24: 203-2406-30
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure1General1
2026-06-301
Active Exploitation1
Full discourse3 posts
  • iOSuptodate@iosuptodate
    Active Exploitation

    iOS 26.5.2 the update you can’t skip 3 reasons to update ASAP: 1. Security - Patches CVE-2026-4721. Real exploit in the wild 2. Stability - Safari tabs stop reloading randomly 3. Battery - Finally fixes 8% overnight drain No major bugs reported yet. Comment “UPDATED” if done https://t.co/sD1XgQuU20

    Post summary

    The iOS 26.5.2 update patches CVE-2026-4721 and confirms that the vulnerability is being actively exploited in the wild, urging users to update immediately.

    2302245.5K
    77 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4721 Memory Safety Vulnerabilities in Firefox and Thunderbird Versions Below 149 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4721

    Post summary

    A new memory‑safety vulnerability (CVE‑2026‑4721) impacting Firefox and Thunderbird below version 149 has been disclosed, without any PoC, exploit, or mitigation details provided.

    0000041
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4721 Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memor… https://www.cve.org/CVERecord?id=CVE-2026-4721

    Post summary

    The post briefly notes that CVE-2026‑4721 involves memory safety bugs in several Mozilla products but offers no further detail on exploitation, patching, or proof of concept.

    0000095
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more