PT-2026-21729 · Mozilla · Firefox+1

Gary Kwong

·

Published

2026-02-24

·

Updated

2026-05-11

·

CVE-2026-2796

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 148 Thunderbird versions prior to 148
Description A JIT miscompilation issue exists in the JavaScript: WebAssembly component. JIT (Just-In-Time) compilation is a method used by browsers to improve execution speed by compiling code during runtime. This flaw can lead to a sequence of failures including use-after-free, type confusion, memory leak, and arbitrary read/write, potentially resulting in remote code execution.
Recommendations Update Firefox to version 148 or later. Update Thunderbird to version 148 or later.

Exploit

Fix

RCE

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2026-06194
CVE-2026-2796
OPENSUSE-SU-2026:10257-1

Affected Products

Firefox
Thunderbird