CVE-2026-8975: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.36 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.11 - Upgrade
Upgrade
Firefox ESR 115to a version that resolves this vulnerability.Fixed in 115.36 - Upgrade
Upgrade
Firefox ESR 140to a version that resolves this vulnerability.Fixed in 140.11 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Thunderbird 140to a version that resolves this vulnerability.Fixed in 140.11 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 151
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-8946
- CVE-2026-8388
- CVE-2026-8947
- CVE-2026-8391
- CVE-2026-8401
- CVE-2026-8953
- CVE-2026-8975
- CVE-2026-8945
- CVE-2026-8948
- CVE-2026-8949
- CVE-2026-8950
- CVE-2026-8951
- CVE-2026-8952
- CVE-2026-8954
- CVE-2026-8955
- CVE-2026-8956
- CVE-2026-8957
- CVE-2026-8958
- CVE-2026-8959
- CVE-2026-8960
- CVE-2026-8961
- CVE-2026-8962
- CVE-2026-8963
- CVE-2026-8964
- CVE-2026-8965
- CVE-2026-8966
- CVE-2026-8967
- CVE-2026-8968
- CVE-2026-8969
- CVE-2026-8970
- CVE-2026-8971
- CVE-2026-8972
- CVE-2026-8973
- CVE-2026-8974
Frequently Asked Questions
What is the severity of CVE-2026-8975?
CVE-2026-8975 has been classified as a high severity vulnerability due to the potential for memory corruption exploits.
How do I fix CVE-2026-8975?
To fix CVE-2026-8975, update to Thunderbird 140.11 or 151, or Firefox ESR 115.36, 140.11, or Firefox 151.
What software is affected by CVE-2026-8975?
CVE-2026-8975 affects Thunderbird versions prior to 140.11 and 151, and Firefox ESR versions prior to 115.36 and 140.11.
What types of vulnerabilities are associated with CVE-2026-8975?
CVE-2026-8975 is associated with memory safety bugs that could lead to memory corruption.
Is it possible to exploit CVE-2026-8975?
Yes, CVE-2026-8975 potentially allows for exploitation if an attacker can leverage the memory safety bugs.