PatchSiren cyber security CVE debrief
CVE-2026-2796 Mozilla CVE debrief
CVE-2026-2796 is a critical vulnerability in the JavaScript: WebAssembly component of Mozilla Firefox and Thunderbird. The vulnerability, which has a CVSS score of 9.8, was fixed in Firefox 148 and Thunderbird 148. This vulnerability involves a Just-In-Time (JIT) miscompilation issue. The CVE was published on February 24, 2026, and last modified on June 30, 2026. The vulnerability affects Firefox versions prior to 148 and Thunderbird versions prior to 148.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-24
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-02-24
- Advisory updated
- 2026-07-15
Who should care
This vulnerability affects users of Mozilla Firefox and Thunderbird. Specifically, any user with a version of Firefox earlier than 148 or Thunderbird earlier than 148 is vulnerable. Given the critical severity and high CVSS score, users should update to the latest versions as soon as possible to mitigate potential risks.
Technical summary
CVE-2026-2796 is a critical vulnerability in the JavaScript: WebAssembly component. It results from a JIT miscompilation issue, which can lead to high impacts on confidentiality, integrity, and availability. The vulnerability has been assigned a CVSS score of 9.8, indicating a critical severity level. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating that the vulnerability can be exploited over the network with low attack complexity and no privileges required. The weakness associated with this vulnerability is CWE-843.
Defensive priority
High. This vulnerability has a critical CVSS score of 9.8 and affects widely used software (Firefox and Thunderbird), making it a high priority for defenders to address.
Recommended defensive actions
- Update Firefox to version 148 or later.
- Update Thunderbird to version 148 or later.
- Ensure all users of Firefox and Thunderbird within the organization are updated to the secure versions.
- Monitor for any unusual activity that could be related to exploitation of this vulnerability.
- Consider implementing additional security measures for high-risk users or environments.
Evidence notes
The CVE-2026-2796 vulnerability was published on February 24, 2026, and last modified on June 30, 2026. It was fixed in Firefox 148 and Thunderbird 148. The vulnerability is a JIT miscompilation issue in the JavaScript: WebAssembly component. The CVSS score is 9.8, indicating critical severity. The CVE details and references can be found on the official CVE website and NVD database.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-2796 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-2796
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-2796 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2796
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-13/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-16/
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-2796
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2796.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.