What is CVE-2026-0891?
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
Timeline
- 2026-01-13Published to the U.S. National Vulnerability Database (NVD)
- 2026-03-20First covered in a defend.network daily briefing
- 2026-07-15NVD record last updated
Affected product
Mozilla Firefox
NVD also lists CPE entries for: Mozilla Firefox, Mozilla Thunderbird
Remediation Steps
- Upgrade FortiOS to version 7.4.5 or 7.2.9 immediately.
- If upgrade is not immediately possible, disable HTTP/HTTPS administrative access from the internet.
- Audit FortiGate admin accounts for unauthorized new accounts or modified permissions.
- Review firewall logs for suspicious authentication attempts from external IPs.
- Rotate all FortiGate admin credentials after patching.
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.