theinfosecnews

CVE-2019-17026

CISA KEV

Published November 3, 2021 · Updated April 3, 2026

high
Official Description+

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

Affected Products

VendorProduct
MozillaFirefox and Thunderbird

Patch Status

Patch by 2022-05-03

Recommended Actions

  1. Check if your systems use any of the affected products listed above.
  2. Apply vendor patches immediately if available.
  3. This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
  4. Monitor vendor advisories for updates and additional mitigations.
  5. Review logs for indicators of compromise related to CVE-2019-17026.