# Mozilla released patches for 41 vulnerabilities in Firefox, Firefox ESR, and Firefox for…

Published: 2026-05-20 · Severity: critical
Canonical: https://vorant.io/reports/4421995b-0efa-4604-8dda-d1fbd1cd9033/mozilla-released-patches-for-41-vulnerabilities-in-firefox-firefox-esr-and

> Mozilla released patches for 41 vulnerabilities in Firefox, Firefox ESR, and Firefox for iOS, including critical flaws enabling arbitrary code execution and sandbox escapes.

Mozilla has addressed multiple vulnerabilities across its browser products including Firefox 151, Firefox ESR 140.11 and 115.36, and Firefox for iOS 151.0. The most critical vulnerabilities could allow remote arbitrary code execution through drive-by compromise attacks. High-severity issues include multiple sandbox escape vulnerabilities in Profile Backup, Android versions, and Disability Access APIs components, along with use-after-free conditions in the DOM and memory safety bugs across the JavaScript Engine and Audio/Video subsystems.

The vulnerability set includes numerous same-origin policy bypasses, privilege escalation vectors in DOM, Application Update, and WebRTC components, and information disclosure issues affecting Security, Graphics, and IP Protection modules. Additional flaws involve integer overflows, spoofing attacks against toolbars and form autofill, and mitigation bypasses. The advisory maps these vulnerabilities to MITRE ATT&CK technique T1189 (Drive-by Compromise) under the Initial Access tactic.

No active exploitation has been observed in the wild. Impact depends on user privilege levels, with administrative accounts facing higher risk. Organizations are advised to apply patches immediately after testing and implement defense-in-depth controls including least privilege, exploit protection, URL filtering, application allowlisting, and endpoint detection capabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8388, CVE-2026-8391, CVE-2026-8401, CVE-2026-8706, CVE-2026-8945, CVE-2026-8946, CVE-2026-8947, CVE-2026-8948, CVE-2026-8949, CVE-2026-8950, CVE-2026-8951, CVE-2026-8952, CVE-2026-8953, CVE-2026-8954, CVE-2026-8955, CVE-2026-8956, CVE-2026-8957, CVE-2026-8958, CVE-2026-8959, CVE-2026-8960, CVE-2026-8961, CVE-2026-8962, CVE-2026-8963, CVE-2026-8964, CVE-2026-8965, CVE-2026-8966, CVE-2026-8967, CVE-2026-8968, CVE-2026-8969, CVE-2026-8970, CVE-2026-8971, CVE-2026-8972, CVE-2026-8973, CVE-2026-8974, CVE-2026-8975

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-052

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4421995b-0efa-4604-8dda-d1fbd1cd9033/mozilla-released-patches-for-41-vulnerabilities-in-firefox-firefox-esr-and.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
