CVE-2026-2764
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
- Affected products
- Firefox, Firefox Esr, Rocky Linux, Thunderbird
- Mozilla Firefox
- < 115.33.0, 148.0, 140.8.0
- Mozilla Thunderbird
- < 140.8.0, 148.0
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.5% (38th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2026-02-24
CVE-2026-2764 at NVD
1 known exploit for CVE-2026-2764
Proof-of-concept code and exploit modules indexed by Sploitus