# Mozilla Patches Dozens of Firefox, Thunderbird Flaws

Published: 2026-04-21 · Severity: medium
Canonical: https://vorant.io/reports/0f4d9ee6-ec9a-5e8e-9382-b4cebaac14df/mozilla-patches-dozens-of-firefox-thunderbird-flaws

> Mozilla fixed multiple vulnerabilities in Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR, some allowing arbitrary code execution; no known exploitation in the wild.

Mozilla has released updates addressing a large batch of vulnerabilities across Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The most severe issues include use-after-free bugs in the DOM, WebRTC, and JavaScript Engine components, along with uninitialized memory issues in Audio/Video and Graphics subsystems, several of which could lead to arbitrary code execution if a user is lured to a malicious page or content (drive-by compromise). Additional lower-severity issues include information disclosure, privilege escalation, spoofing, mitigation bypasses, and denial-of-service conditions spread across NSS libraries, networking, storage, and form autofill components.

CISA/MS-ISAC notes there are currently no reports of in-the-wild exploitation for any of these CVEs. However, given the scope of affected components and the presence of multiple memory-safety and use-after-free bugs, successful exploitation of the most severe flaws could grant an attacker code execution with the privileges of the logged-in user, potentially enabling data theft, account creation, or further compromise depending on user privilege levels.

Organizations should prioritize patching to the fixed versions (Firefox 150, Firefox ESR 140.10/115.35, Thunderbird 150, Thunderbird ESR 140.10) through standard patch management processes. Standard mitigations such as least-privilege enforcement, exploit protection, application allowlisting, and web-content restrictions are recommended to reduce the impact of any future exploitation attempts.

## Mentioned in this report

- Vulnerabilities: CVE-2026-2781, CVE-2026-6746, CVE-2026-6747, CVE-2026-6748, CVE-2026-6749, CVE-2026-6750, CVE-2026-6751, CVE-2026-6752, CVE-2026-6753, CVE-2026-6754, CVE-2026-6755, CVE-2026-6756, CVE-2026-6757, CVE-2026-6758, CVE-2026-6759, CVE-2026-6760, CVE-2026-6761, CVE-2026-6762, CVE-2026-6763, CVE-2026-6764, CVE-2026-6765, CVE-2026-6766, CVE-2026-6767, CVE-2026-6768, CVE-2026-6769, CVE-2026-6770, CVE-2026-6771, CVE-2026-6772, CVE-2026-6773, CVE-2026-6774, CVE-2026-6775, CVE-2026-6776, CVE-2026-6777, CVE-2026-6778, CVE-2026-6779, CVE-2026-6780, CVE-2026-6781, CVE-2026-6784, CVE-2026-6785, CVE-2026-6786

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-038

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0f4d9ee6-ec9a-5e8e-9382-b4cebaac14df/mozilla-patches-dozens-of-firefox-thunderbird-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
