VORANT. Threat Intelligence Sign in Get the full feed

Mozilla Patches Firefox, Thunderbird Code Execution Flaws

medium vulnerability

Mozilla fixed multiple vulnerabilities in Firefox and Thunderbird, including memory safety bugs that could allow arbitrary code execution.

Mozilla has disclosed and patched several vulnerabilities affecting Firefox and Thunderbird, the most severe of which could enable arbitrary code execution if exploited. The flaws include a denial-of-service issue triggered via a malicious LDAP address-book server, a chat UI manipulation vulnerability through injection, and memory safety bugs resolved in Firefox 152.0.4. Successful exploitation could allow an attacker to install programs, manipulate or delete data, or create new accounts with full user rights, with impact scaled by the privilege level of the affected user account.

No evidence of in-the-wild exploitation has been reported at this time. Affected versions include Firefox prior to 152.0.4, Thunderbird prior to 152.0.1, and Thunderbird prior to 140.12.1. MS-ISAC recommends prompt patching, least-privilege configurations, exploit protection features, and web/email content restrictions to mitigate risk pending update deployment.

Mentioned in this report

Vulnerabilities CVE-2026-14241CVE-2026-57962CVE-2026-57963

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-065

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free