CVE-2026-0891
published 2026-01-13CVE-2026-0891: Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory…
PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.41%
33.6th percentile
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 147.0-1 (sid) | firefox 147.0-1 (sid) |
| debian | firefox-esr | < firefox 147.0-1 (sid) | firefox 147.0-1 (sid) |
| debian | thunderbird | < firefox 147.0-1 (sid) | firefox 147.0-1 (sid) |
| mozilla | firefox | < 140.7.0 | 140.7.0 |
| mozilla | firefox | < 147.0 | 147.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 140.7.0 | 140.7.0 |
| mozilla | thunderbird | < 147.0 | 147.0 |
| mozilla | thunderbird | >= 0 < 1:140.7.0esr-1~deb11u1 | 1:140.7.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:140.7.0esr-1~deb12u1 | 1:140.7.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:140.7.0esr-1~deb13u1 | 1:140.7.0esr-1~deb13u1 |
| mozilla | thunderbird | >= 0 < 1:140.7.0esr-1 | 1:140.7.0esr-1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
vendor_redhat·2026-01-13·CVSS 8.1
CVE-2026-0891 [HIGH] firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with
Debian
CVE-2026-0891: firefox - Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox ...
vendor_debian·2026·CVSS 8.1
CVE-2026-0891 [HIGH] CVE-2026-0891: firefox - Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox ...
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
Mozilla
Mozilla Foundation Security Advisory 2026-05: CVE-2026-0891
vendor_mozilla·CVSS 8.1
CVE-2026-0891 [HIGH] Mozilla Foundation Security Advisory 2026-05: CVE-2026-0891
Mozilla Foundation Security Advisory 2026-05
CVE: CVE-2026-0891
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.7
Mozilla
Mozilla Foundation Security Advisory 2026-03: CVE-2026-0891
vendor_mozilla·CVSS 8.1
CVE-2026-0891 [HIGH] Mozilla Foundation Security Advisory 2026-03: CVE-2026-0891
Mozilla Foundation Security Advisory 2026-03
CVE: CVE-2026-0891
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.7
Mozilla
Mozilla Foundation Security Advisory 2026-01: CVE-2026-0891
vendor_mozilla·CVSS 8.1
CVE-2026-0891 [HIGH] Mozilla Foundation Security Advisory 2026-01: CVE-2026-0891
Mozilla Foundation Security Advisory 2026-01
CVE: CVE-2026-0891
Product: Firefox
Impact: moderate
Fixed in: Firefox 147
Mozilla
Mozilla Foundation Security Advisory 2026-04: CVE-2026-0891
vendor_mozilla·CVSS 8.1
CVE-2026-0891 [HIGH] Mozilla Foundation Security Advisory 2026-04: CVE-2026-0891
Mozilla Foundation Security Advisory 2026-04
CVE: CVE-2026-0891
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 147
VulDB
Mozilla Thunderbird up to 146 memory corruption (Nessus ID 284821 / WID-SEC-2026-0090)
vuldb·2026-06-12·CVSS 8.1
CVE-2026-0891 [HIGH] Mozilla Thunderbird up to 146 memory corruption (Nessus ID 284821 / WID-SEC-2026-0090)
A vulnerability classified as critical was found in Mozilla Thunderbird up to 146. The impacted element is an unknown function. The manipulation results in memory corruption.
This vulnerability was named CVE-2026-0891. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
VulDB
Mozilla Firefox up to 146 memory corruption (Nessus ID 284821 / WID-SEC-2026-0090)
vuldb·2026-06-12·CVSS 8.1
CVE-2026-0891 [HIGH] Mozilla Firefox up to 146 memory corruption (Nessus ID 284821 / WID-SEC-2026-0090)
A vulnerability classified as critical has been found in Mozilla Firefox up to 146. The affected element is an unknown function. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2026-0891. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
OSV
CVE-2026-0891: Memory safety bugs present in Firefox ESR 140
osv·2026-01-13·CVSS 8.1
CVE-2026-0891 [HIGH] CVE-2026-0891: Memory safety bugs present in Firefox ESR 140
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
GHSA
GHSA-w588-qjhp-fm98: Memory safety bugs present in Firefox ESR 140
ghsa_unreviewed·2026-01-13
CVE-2026-0891 [HIGH] CWE-119 GHSA-w588-qjhp-fm98: Memory safety bugs present in Firefox ESR 140
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.
No detection rules found.
No public exploits indexed.
Krebs
Patch Tuesday, January 2026 Edition
blogs_krebs·2026-01-14·CVSS 5.5
CVE-2026-20805 [MEDIUM] Patch Tuesday, January 2026 Edition
Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft’s most-dire “critical” rating, and the company warns that attackers are already exploiting one of the bugs fixed today.
January’s Microsoft zero-day flaw — CVE-2026-20805 — is brought to us by a flaw in the Desktop Window Manager (DWM), a key component of Windows that organizes windows on a user’s screen. Kev Breen , senior director of cyber threat research at Immersive , said despite awarding CVE-2026-20805 a middling CVSS score of 5.5, Microsoft has confirmed its active exploitation in the wild, indicating that threat actors are already leveraging this flaw against organizations.
Breen said vulnerabilities of t
Krebs
Patch Tuesday, January 2026 Edition
blogs_krebs·2026-01-13·CVSS 5.5
CVE-2026-20805 [MEDIUM] Patch Tuesday, January 2026 Edition
Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft’s most-dire “critical” rating, and the company warns that attackers are already exploiting one of the bugs fixed today.
January’s Microsoft zero-day flaw — CVE-2026-20805 — is brought to us by a flaw in the Desktop Window Manager (DWM), a key component of Windows that organizes windows on a user’s screen. Kev Breen, senior director of cyber threat research at Immersive, said despite awarding CVE-2026-20805 a middling CVSS score of 5.5, Microsoft has confirmed its active exploitation in the wild, indicating that threat actors are already leveraging this flaw against organizations.
Breen said vulnerabilities of thi
Wiz
CVE-2026-0891 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-0891 [HIGH] CVE-2026-0891 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0891 :
NixOS vulnerability analysis and mitigation
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Source : NVD
## 8.1
Score
Published January 13, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
MozillaFiref
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1964722%2C2000981%2C2003100%2C2003278https://www.mozilla.org/security/advisories/mfsa2026-01/https://www.mozilla.org/security/advisories/mfsa2026-03/https://www.mozilla.org/security/advisories/mfsa2026-04/https://www.mozilla.org/security/advisories/mfsa2026-05/https://access.redhat.com/errata/RHSA-2026:0667https://access.redhat.com/errata/RHSA-2026:0694https://access.redhat.com/errata/RHSA-2026:0924https://access.redhat.com/errata/RHSA-2026:1320https://access.redhat.com/errata/RHSA-2026:1413https://access.redhat.com/errata/RHSA-2026:1414https://access.redhat.com/errata/RHSA-2026:1415https://access.redhat.com/errata/RHSA-2026:1461https://access.redhat.com/errata/RHSA-2026:1462https://access.redhat.com/errata/RHSA-2026:1471https://access.redhat.com/errata/RHSA-2026:1487https://access.redhat.com/errata/RHSA-2026:2041https://access.redhat.com/errata/RHSA-2026:2043https://access.redhat.com/errata/RHSA-2026:2044https://access.redhat.com/errata/RHSA-2026:2047https://access.redhat.com/errata/RHSA-2026:2069https://access.redhat.com/errata/RHSA-2026:2070https://access.redhat.com/errata/RHSA-2026:2073https://access.redhat.com/errata/RHSA-2026:2074https://access.redhat.com/errata/RHSA-2026:2220https://access.redhat.com/errata/RHSA-2026:2231https://access.redhat.com/errata/RHSA-2026:2271https://access.redhat.com/errata/RHSA-2026:2286https://access.redhat.com/security/cve/CVE-2026-0891https://bugzilla.redhat.com/show_bug.cgi?id=2428963https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0891.json
2026-01-13
Published