Mozilla patches Firefox, Thunderbird memory safety flaws
Mozilla released security updates for Firefox and Thunderbird addressing multiple vulnerabilities including memory safety bugs that could enable arbitrary code execution.
Mozilla has issued security updates to address multiple vulnerabilities in Firefox and Thunderbird, the most severe of which could allow arbitrary code execution. The vulnerabilities affect Firefox versions prior to 152.0.4 and Thunderbird versions prior to 152.0.1 and 140.12.1. The most critical flaw is a memory safety bug (CVE-2026-14241) fixed in Firefox 152.0.4. Additional vulnerabilities include a denial-of-service issue via malicious LDAP address-book servers (CVE-2026-57962) and a chat UI manipulation vulnerability through injection (CVE-2026-57963).
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code, install programs, view or modify data, or create new accounts with full user rights. The impact depends on the privileges of the compromised user account, with administrative accounts facing greater risk. No active exploitation of these vulnerabilities has been reported in the wild.
Organizations should immediately apply the available Mozilla security updates after appropriate testing. Additional mitigations include implementing the principle of least privilege, restricting administrative access, enabling anti-exploitation features, and deploying endpoint detection and response solutions.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-065
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free