CVE-2026-2771
Plain English Summary
AI-powered analysis for quick understanding
This critical vulnerability allows an attacker to execute arbitrary code on a user's system through malicious web content in Firefox and Thunderbird. It affects specific versions of these applications, so users need to ensure they are running the latest updates to stay protected.
Technical Description
Undefined behavior in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 24, 2026
about 1 month ago
Last Modified
Feb 25, 2026
about 1 month ago
Vendor
mozilla
Product
firefox
Related Vulnerabilities
This vulnerability allows an attacker to potentially execute malicious code on a user's system through Firefox or Thunderbird, which could lead to full control over the affected device. It specifically affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.
This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of sensitive information. It affects users running versions earlier than 148 for Firefox and 148 for Thunderbird, meaning those who haven't updated their software are at risk.
This vulnerability allows an attacker to access sensitive information from a user's system through a flaw in Firefox's JavaScript engine. It affects versions of Firefox and Thunderbird before 148 and 140.8, meaning users need to update their software to protect against potential data leaks.
This critical vulnerability allows an attacker to gain higher access privileges within Firefox and Thunderbird, potentially letting them execute harmful actions on a user's system. It affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.
This critical vulnerability allows an attacker to potentially execute malicious code on a user's system through affected versions of Firefox and Thunderbird. It requires the user to visit a specially crafted website or open a malicious email, making it essential for users to update their software to the latest versions to stay protected.