Review reviewCritical
CVE-2026-0881
Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
- CVSS
- 10
- EPSS
- 0.31% 23.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.13