CVE-2026-8092: Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2
Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.35.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.35.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10.2 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 150.0.2 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.10.2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 150.0.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-8092?
CVE-2026-8092 is classified as a memory safety issue which has the potential to allow attackers to exploit memory corruption.
How do I fix CVE-2026-8092?
To fix CVE-2026-8092, upgrade to Thunderbird ESR version 140.10.2 or 150.0.2, or Firefox ESR version 115.35.2 or 140.10.2, or Firefox version 150.0.2.
Which versions are affected by CVE-2026-8092?
Affected versions include Firefox ESR 115.35.1, 140.10.1, and Firefox 150.0.1.
Is Thunderbird affected by CVE-2026-8092?
Yes, Thunderbird versions prior to 140.10.2 and 150.0.2 are affected by CVE-2026-8092.
What are the remediation steps for CVE-2026-8092?
To remediate CVE-2026-8092, update the affected software to the latest versions specified in the vulnerability advisory.