CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.34 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.9 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 149 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.34 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.9 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 149 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.9
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-4684
- CVE-2026-4685
- CVE-2026-4686
- CVE-2026-4687
- CVE-2026-4688
- CVE-2026-4689
- CVE-2026-4690
- CVE-2026-4691
- CVE-2026-4692
- CVE-2026-4693
- CVE-2026-4694
- CVE-2026-4695
- CVE-2026-4696
- CVE-2026-4697
- CVE-2026-4698
- CVE-2026-4699
- CVE-2026-4700
- CVE-2026-4701
- CVE-2026-4722
- CVE-2026-4702
- CVE-2026-4723
- CVE-2026-4724
- CVE-2026-4704
- CVE-2026-4705
- CVE-2026-4706
- CVE-2026-4707
- CVE-2026-4708
- CVE-2026-4709
- CVE-2026-4710
- CVE-2026-4711
- CVE-2026-4725
- CVE-2026-4712
- CVE-2026-4713
- CVE-2026-4714
- CVE-2026-4715
- CVE-2026-4716
- CVE-2026-4717
- CVE-2026-4726
- CVE-2025-59375
- CVE-2026-4727
- CVE-2026-4728
- CVE-2026-4718
- CVE-2026-4719
- CVE-2026-4720
- CVE-2026-4729
- CVE-2026-4721
- CVE-2026-3889
- CVE-2026-4371
Frequently Asked Questions
What is the severity of CVE-2026-4721?
CVE-2026-4721 is classified as a high severity vulnerability due to the risk of memory corruption that could lead to arbitrary code execution.
How do I fix CVE-2026-4721?
To fix CVE-2026-4721, update your Mozilla Firefox or Thunderbird to the latest versions which are not affected by the vulnerability.
Which versions are affected by CVE-2026-4721?
CVE-2026-4721 affects Firefox up to version 148, Firefox ESR versions up to 115.33 and 140.8, and Thunderbird versions up to 148.
What type of vulnerabilities does CVE-2026-4721 address?
CVE-2026-4721 addresses memory safety bugs that could potentially allow attackers to corrupt memory.
Is CVE-2026-4721 applicable to both Firefox and Thunderbird?
Yes, CVE-2026-4721 affects both Mozilla Firefox and Mozilla Thunderbird applications.