Mozilla patches 40+ flaws in Firefox, Thunderbird
Mozilla released updates addressing multiple vulnerabilities in Firefox and Thunderbird, including use-after-free and memory safety bugs that could enable arbitrary code execution.
Mozilla has released security updates addressing over 40 vulnerabilities across Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The most severe flaws include use-after-free vulnerabilities in the DOM (CVE-2026-6746), WebRTC component (CVE-2026-6747, CVE-2026-6752, CVE-2026-6753), and JavaScript Engine (CVE-2026-6754), along with multiple memory safety bugs (CVE-2026-6784, CVE-2026-6785, CVE-2026-6786). These vulnerabilities could allow attackers to execute arbitrary code in the context of the affected application.
Additional vulnerabilities include privilege escalation flaws in the Graphics and Networking components, information disclosure issues, boundary condition errors, and denial-of-service conditions. Affected versions include Firefox prior to 150, Firefox ESR prior to 140.10 and 115.35, Thunderbird prior to 150, and Thunderbird ESR prior to 140.10. The MS-ISAC reports no active exploitation in the wild at the time of publication.
Organizations should apply the available updates immediately after appropriate testing. The vulnerabilities primarily affect users through drive-by compromise tactics, where visiting a malicious website or opening a crafted email could trigger exploitation. Impact severity depends on user privilege levels, with administrative accounts facing greater risk than standard user accounts.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-038
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free