CVE-2019-17026: Mozilla Firefox And Thunderbird Type Confusion Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 46.3% chance of exploitation in the next 30 days.

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only
  • Mozilla Firefox: before 68.4.1 (fixed in 68.4.1); before 72.0.1 (fixed in 72.0.1)
  • Mozilla Thunderbird: before 68.4.1 (fixed in 68.4.1)

Published 2020-03-02. Last modified 2026-06-17.