Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

Old Firefox and Thunderbird versions open to network cache attack

CVE-2026-2791
Summary

Users of outdated Firefox and Thunderbird versions are at risk of a security attack that can bypass protection. This means an attacker could potentially access sensitive information or disrupt your system. Update to the latest version to protect yourself.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
mozilla firefox <= 140.8.0
mozilla firefox <= 148.0
mozilla thunderbird <= 140.8.0
mozilla thunderbird <= 148.0
Original title
Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Original description
Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
nvd CVSS3.1 9.8
Vulnerability type
CWE-288 Authentication Bypass Using Alternate Path
Published: 24 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026