CVE-2026-16361: Memory safety bugs fixed in Thunderbird ESR 140.13
Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.13 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.38 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.13 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.13
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-15719
- CVE-2026-16349
- CVE-2026-16350
- CVE-2026-16351
- CVE-2026-16352
- CVE-2026-16353
- CVE-2026-16354
- CVE-2026-16355
- CVE-2026-16356
- CVE-2026-16357
- CVE-2026-16358
- CVE-2026-16359
- CVE-2026-16360
- CVE-2026-16361
- CVE-2026-15718
- CVE-2026-16362
- CVE-2026-16363
- CVE-2026-16368
- CVE-2026-16369
- CVE-2026-16371
- CVE-2026-16374
- CVE-2026-16375
- CVE-2026-16377
- CVE-2026-16379
- CVE-2026-16381
- CVE-2026-16383
- CVE-2026-16387
- CVE-2026-16390
- CVE-2026-16391
- CVE-2026-16396
- CVE-2026-16405
- CVE-2026-16412
- CVE-2026-14899
Frequently Asked Questions
What is the severity of CVE-2026-16361?
CVE-2026-16361 has a critical severity rating of 9.8 according to the CVSS 3.1 metrics.
How do I fix CVE-2026-16361?
To fix CVE-2026-16361, users should update to Firefox ESR version 115.38 or 140.13.
What types of vulnerabilities are associated with CVE-2026-16361?
CVE-2026-16361 is associated with memory safety bugs, specifically memory corruption and potential buffer overflow vulnerabilities.
What software is affected by CVE-2026-16361?
CVE-2026-16361 affects Mozilla Firefox ESR versions 115.37 and 140.12, as well as Mozilla Thunderbird.
Can CVE-2026-16361 be exploited to run arbitrary code?
Yes, while exploiting CVE-2026-16361 may require significant effort, some memory safety bugs could potentially allow for arbitrary code execution.