CVE-2026-0892
published 2026-01-13CVE-2026-0892: Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.40%
32.7th percentile
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 147.0-1 (sid) | firefox 147.0-1 (sid) |
| mozilla | firefox | < 147.0 | 147.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 147.0 | 147.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 146 memory corruption (Nessus ID 284838 / WID-SEC-2026-0090)
vuldb·2026-06-12·CVSS 9.8
CVE-2026-0892 [CRITICAL] Mozilla Firefox up to 146 memory corruption (Nessus ID 284838 / WID-SEC-2026-0090)
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 146. This affects an unknown function. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2026-0892. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
VulDB
Mozilla Thunderbird up to 146 memory corruption (Nessus ID 284838 / WID-SEC-2026-0090)
vuldb·2026-06-12·CVSS 9.8
CVE-2026-0892 [CRITICAL] Mozilla Thunderbird up to 146 memory corruption (Nessus ID 284838 / WID-SEC-2026-0090)
A vulnerability, which was classified as critical, was found in Mozilla Thunderbird up to 146. This impacts an unknown function. Such manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2026-0892. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-3m78-88vj-q2rf: Memory safety bugs present in Firefox 146 and Thunderbird 146
ghsa_unreviewed·2026-01-13
CVE-2026-0892 [CRITICAL] CWE-119 GHSA-3m78-88vj-q2rf: Memory safety bugs present in Firefox 146 and Thunderbird 146
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147.
OSV
CVE-2026-0892: Memory safety bugs present in Firefox 146 and Thunderbird 146
osv·2026-01-13·CVSS 9.8
CVE-2026-0892 [CRITICAL] CVE-2026-0892: Memory safety bugs present in Firefox 146 and Thunderbird 146
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.
Red Hat
firefox: thunderbird: Memory safety bugs fixed in Firefox 147 and Thunderbird 147
vendor_redhat·2026-01-13·CVSS 9.8
CVE-2026-0892 [CRITICAL] firefox: thunderbird: Memory safety bugs fixed in Firefox 147 and Thunderbird 147
firefox: thunderbird: Memory safety bugs fixed in Firefox 147 and Thunderbird 147
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the M
Debian
CVE-2026-0892: firefox - Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bug...
vendor_debian·2026·CVSS 9.8
CVE-2026-0892 [CRITICAL] CVE-2026-0892: firefox - Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bug...
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.
Scope: local
sid: resolved (fixed in 147.0-1)
Mozilla
Mozilla Foundation Security Advisory 2026-04: CVE-2026-0892
vendor_mozilla·CVSS 9.8
CVE-2026-0892 [CRITICAL] Mozilla Foundation Security Advisory 2026-04: CVE-2026-0892
Mozilla Foundation Security Advisory 2026-04
CVE: CVE-2026-0892
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 147
Mozilla
Mozilla Foundation Security Advisory 2026-01: CVE-2026-0892
vendor_mozilla·CVSS 9.8
CVE-2026-0892 [CRITICAL] Mozilla Foundation Security Advisory 2026-01: CVE-2026-0892
Mozilla Foundation Security Advisory 2026-01
CVE: CVE-2026-0892
Product: Firefox
Impact: moderate
Fixed in: Firefox 147
No detection rules found.
No public exploits indexed.
Krebs
Patch Tuesday, January 2026 Edition
blogs_krebs·2026-01-14·CVSS 5.5
CVE-2026-20805 [MEDIUM] Patch Tuesday, January 2026 Edition
Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft’s most-dire “critical” rating, and the company warns that attackers are already exploiting one of the bugs fixed today.
January’s Microsoft zero-day flaw — CVE-2026-20805 — is brought to us by a flaw in the Desktop Window Manager (DWM), a key component of Windows that organizes windows on a user’s screen. Kev Breen , senior director of cyber threat research at Immersive , said despite awarding CVE-2026-20805 a middling CVSS score of 5.5, Microsoft has confirmed its active exploitation in the wild, indicating that threat actors are already leveraging this flaw against organizations.
Breen said vulnerabilities of t
Krebs
Patch Tuesday, January 2026 Edition
blogs_krebs·2026-01-13·CVSS 5.5
CVE-2026-20805 [MEDIUM] Patch Tuesday, January 2026 Edition
Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft’s most-dire “critical” rating, and the company warns that attackers are already exploiting one of the bugs fixed today.
January’s Microsoft zero-day flaw — CVE-2026-20805 — is brought to us by a flaw in the Desktop Window Manager (DWM), a key component of Windows that organizes windows on a user’s screen. Kev Breen, senior director of cyber threat research at Immersive, said despite awarding CVE-2026-20805 a middling CVSS score of 5.5, Microsoft has confirmed its active exploitation in the wild, indicating that threat actors are already leveraging this flaw against organizations.
Breen said vulnerabilities of thi
Wiz
CVE-2026-0892 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-0892 [CRITICAL] CVE-2026-0892 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0892 :
NixOS vulnerability analysis and mitigation
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.
Source : NVD
## 9.8
Score
Published January 13, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
thunderbird
cpe:2.3:a:mozilla:firefox
Sources
Homebrew Severity CRITICAL Has Fix Added at: J
2026-01-13
Published