Mozilla Patches Dozens of Firefox, Thunderbird Flaws
Mozilla fixed multiple vulnerabilities in Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR, some allowing arbitrary code execution; no known exploitation in the wild.
Mozilla has released updates addressing a large batch of vulnerabilities across Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The most severe issues include use-after-free bugs in the DOM, WebRTC, and JavaScript Engine components, along with uninitialized memory issues in Audio/Video and Graphics subsystems, several of which could lead to arbitrary code execution if a user is lured to a malicious page or content (drive-by compromise). Additional lower-severity issues include information disclosure, privilege escalation, spoofing, mitigation bypasses, and denial-of-service conditions spread across NSS libraries, networking, storage, and form autofill components.
CISA/MS-ISAC notes there are currently no reports of in-the-wild exploitation for any of these CVEs. However, given the scope of affected components and the presence of multiple memory-safety and use-after-free bugs, successful exploitation of the most severe flaws could grant an attacker code execution with the privileges of the logged-in user, potentially enabling data theft, account creation, or further compromise depending on user privilege levels.
Organizations should prioritize patching to the fixed versions (Firefox 150, Firefox ESR 140.10/115.35, Thunderbird 150, Thunderbird ESR 140.10) through standard patch management processes. Standard mitigations such as least-privilege enforcement, exploit protection, application allowlisting, and web-content restrictions are recommended to reduce the impact of any future exploitation attempts.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-038
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free