CVE-2026-7324
published 2026-04-28CVE-2026-7324: Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
PriorityP343high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.30%
21.9th percentile
Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150.0.1 | Firefox 150.0.1 |
| mozilla | firefox | < 150.0.1 | 150.0.1 |
| mozilla | thunderbird | < Thunderbird 150.0.1 | Thunderbird 150.0.1 |
| mozilla | thunderbird | < 150.0.1 | 150.0.1 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j2rp-6m32-crr3: Memory safety bugs present in Firefox 150
ghsa_unreviewed·2026-04-28
CVE-2026-7324 [HIGH] CWE-119 GHSA-j2rp-6m32-crr3: Memory safety bugs present in Firefox 150
Memory safety bugs present in Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1.
VulDB
Mozilla Firefox up to 150.0.0 memory corruption (EUVD-2026-26061)
vuldb·2026-04-28·CVSS 7.3
CVE-2026-7324 [HIGH] Mozilla Firefox up to 150.0.0 memory corruption (EUVD-2026-26061)
A vulnerability has been found in Mozilla Firefox up to 150.0.0 and classified as critical. Affected is an unknown function. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2026-7324. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
VulDB
Mozilla Thunderbird up to 150.0.0 memory corruption
vuldb·2026-04-28·CVSS 7.3
CVE-2026-7324 [HIGH] Mozilla Thunderbird up to 150.0.0 memory corruption
A vulnerability was found in Mozilla Thunderbird up to 150.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to memory corruption.
This vulnerability is handled as CVE-2026-7324. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
Red Hat
firefox: Memory safety bugs fixed in Firefox 150.0.1
vendor_redhat·2026-04-28·CVSS 7.3
CVE-2026-7324 [HIGH] firefox: Memory safety bugs fixed in Firefox 150.0.1
firefox: Memory safety bugs fixed in Firefox 150.0.1
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8
Mozilla
Mozilla Foundation Security Advisory 2026-35: CVE-2026-7324
vendor_mozilla
CVE-2026-7324 Mozilla Foundation Security Advisory 2026-35: CVE-2026-7324
Mozilla Foundation Security Advisory 2026-35
CVE: CVE-2026-7324
Product: Firefox
Impact: high
Fixed in: Firefox 150.0.1
Mozilla
Mozilla Foundation Security Advisory 2026-38: CVE-2026-7324
vendor_mozilla·CVSS 7.3
CVE-2026-7324 [HIGH] Mozilla Foundation Security Advisory 2026-38: CVE-2026-7324
Mozilla Foundation Security Advisory 2026-38
CVE: CVE-2026-7324
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150.0.1
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
blogs_hackernews·2026-05-04·CVSS 9.3
CVE-2026-41940 [CRITICAL] ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
This week, the shadows moved faster than the patches.
While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems.
The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling operations like legitimate businesses — except their product is chaos. And the underground is getting uncomfortably professional.
Here’s the full week
Bugzilla
CVE-2026-7324 firefox: Memory safety bugs fixed in Firefox 150.0.1
bugzilla·2026-04-28·CVSS 7.3
CVE-2026-7324 [HIGH] CVE-2026-7324 firefox: Memory safety bugs fixed in Firefox 150.0.1
CVE-2026-7324 firefox: Memory safety bugs fixed in Firefox 150.0.1
Memory safety bugs present in Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1.
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029419%2C2029717%2C2029769%2C2029886https://www.mozilla.org/security/advisories/mfsa2026-35/https://www.mozilla.org/security/advisories/mfsa2026-38/https://access.redhat.com/security/cve/CVE-2026-7324https://bugzilla.redhat.com/show_bug.cgi?id=2463482https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7324.json
2026-04-28
Published