CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-4684
- CVE-2026-4685
- CVE-2026-4686
- CVE-2026-4687
- CVE-2026-4688
- CVE-2026-4689
- CVE-2026-4690
- CVE-2026-4691
- CVE-2026-4692
- CVE-2026-4693
- CVE-2026-4694
- CVE-2026-4695
- CVE-2026-4696
- CVE-2026-4697
- CVE-2026-4698
- CVE-2026-4699
- CVE-2026-4700
- CVE-2026-4701
- CVE-2026-4722
- CVE-2026-4702
- CVE-2026-4723
- CVE-2026-4724
- CVE-2026-4704
- CVE-2026-4705
- CVE-2026-4706
- CVE-2026-4707
- CVE-2026-4708
- CVE-2026-4709
- CVE-2026-4710
- CVE-2026-4711
- CVE-2026-4725
- CVE-2026-4712
- CVE-2026-4713
- CVE-2026-4714
- CVE-2026-4715
- CVE-2026-4716
- CVE-2026-4717
- CVE-2026-4726
- CVE-2025-59375
- CVE-2026-4727
- CVE-2026-4728
- CVE-2026-4718
- CVE-2026-4719
- CVE-2026-4720
- CVE-2026-4729
- CVE-2026-4721
- CVE-2026-3889
- CVE-2026-4371
Frequently Asked Questions
What is the severity of CVE-2026-4720?
The severity of CVE-2026-4720 is considered high due to the potential for memory corruption.
How do I fix CVE-2026-4720?
To fix CVE-2026-4720, users should update to Firefox ESR version 140.9, Thunderbird ESR version 140.9, Firefox version 149, or Thunderbird version 149.
What products are affected by CVE-2026-4720?
CVE-2026-4720 affects Mozilla Firefox versions up to 149, Mozilla Firefox ESR versions up to 140.9, Mozilla Thunderbird versions up to 149, and Mozilla Thunderbird ESR versions up to 140.9.
What types of bugs does CVE-2026-4720 address?
CVE-2026-4720 addresses memory safety bugs that can lead to memory corruption.
Is there evidence of exploitation for CVE-2026-4720?
There is some evidence that indicates the memory safety bugs in CVE-2026-4720 may be exploitable with enough effort.