VORANT. Threat Intelligence Sign in Get the full feed

Mozilla released patches for 41 vulnerabilities in Firefox, Firefox ESR, and Firefox for…

critical vulnerability

Mozilla released patches for 41 vulnerabilities in Firefox, Firefox ESR, and Firefox for iOS, including critical flaws enabling arbitrary code execution and sandbox escapes.

Mozilla has addressed multiple vulnerabilities across its browser products including Firefox 151, Firefox ESR 140.11 and 115.36, and Firefox for iOS 151.0. The most critical vulnerabilities could allow remote arbitrary code execution through drive-by compromise attacks. High-severity issues include multiple sandbox escape vulnerabilities in Profile Backup, Android versions, and Disability Access APIs components, along with use-after-free conditions in the DOM and memory safety bugs across the JavaScript Engine and Audio/Video subsystems.

The vulnerability set includes numerous same-origin policy bypasses, privilege escalation vectors in DOM, Application Update, and WebRTC components, and information disclosure issues affecting Security, Graphics, and IP Protection modules. Additional flaws involve integer overflows, spoofing attacks against toolbars and form autofill, and mitigation bypasses. The advisory maps these vulnerabilities to MITRE ATT&CK technique T1189 (Drive-by Compromise) under the Initial Access tactic.

No active exploitation has been observed in the wild. Impact depends on user privilege levels, with administrative accounts facing higher risk. Organizations are advised to apply patches immediately after testing and implement defense-in-depth controls including least privilege, exploit protection, URL filtering, application allowlisting, and endpoint detection capabilities.

Mentioned in this report

Vulnerabilities CVE-2026-8388CVE-2026-8391CVE-2026-8401CVE-2026-8706CVE-2026-8945CVE-2026-8946CVE-2026-8947CVE-2026-8948CVE-2026-8949CVE-2026-8950CVE-2026-8951CVE-2026-8952CVE-2026-8953CVE-2026-8954CVE-2026-8955CVE-2026-8956CVE-2026-8957CVE-2026-8958CVE-2026-8959CVE-2026-8960CVE-2026-8961CVE-2026-8962CVE-2026-8963CVE-2026-8964CVE-2026-8965CVE-2026-8966CVE-2026-8967CVE-2026-8968CVE-2026-8969CVE-2026-8970CVE-2026-8971CVE-2026-8972CVE-2026-8973CVE-2026-8974CVE-2026-8975

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-052

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free