CVE-2026-7322
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and
CVSS
7.3
High
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Published: Apr 28, 2026 · Last modified: Jul 15, 2026 · CWE-119 · CWE-416 · CWE-787
0.3%EPSS · 30 days0.3%
2026-08-152026-09-12
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2021904%2C2022731%2C2027158%2C2027733%2C2027973%2C2027976%2C2028231%2C2028731%2C2028886%2C2029067%2C2029700%2C2029724%2C2029806%2C2029814%2C2030108%2C2030111%2C2031524%2C2031921%2C2032040
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-35/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-36/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-37/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-38/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-39/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19153
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19157
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19348
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19370
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19588
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:20586
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:21743
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22324
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22408
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22409
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22410
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22708
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22712
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22847
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-905597.5 HIG—
——0snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.1dCVE-2026-892668.2 HIG39.6%
——12stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.2dCVE-2026-542407.4 HIG15.0%
——4libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or writes, potentially disclosing data, corrupting memory, or crashing the decoder. Version 1.1.1 contains a patch.2dCVE-2026-47773—0.9%
——0ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt memory in the ATTClass global object. Devices running ArduinoBLE with one or more characteristics configured with the BLEEncryption property are affected. The fix is included starting from the 2.0.2 release.2dCVE-2026-78547—4.7%
——1Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows.
This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.2dCVE-2026-703418.5 HIG47.7%
——14Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.1d