Mozilla Patches Dozens of Firefox, Thunderbird Flaws
Mozilla fixed over 40 vulnerabilities in Firefox, Firefox ESR, and Thunderbird, several allowing arbitrary code execution, with no known active exploitation.
Mozilla has released updates addressing more than 40 vulnerabilities across Firefox (prior to 152), Firefox ESR (prior to 140.12), Thunderbird (prior to 152), and Thunderbird ESR (prior to 140.12). The most severe issues include sandbox escapes in the DOM, Security, and Networking components, use-after-free bugs in Graphics and Networking, a privilege escalation flaw in Graphics, and JIT miscompilation bugs in the DOM and JavaScript engine — several of which could allow an attacker to achieve arbitrary code execution if a victim visits a malicious page or opens a crafted attachment.
Additional lower-severity issues were also patched, including information disclosure bugs, same-origin policy bypass, mitigation bypass, clickjacking, spoofing, and denial-of-service conditions spread across the Graphics, Networking, Security, Password Manager, and Audio/Video components. MS-ISAC states there are currently no reports of in-the-wild exploitation for any of these vulnerabilities.
Given the volume and severity of the flaws — particularly the sandbox escapes and code-execution bugs — organizations running affected Mozilla products should prioritize patching per standard vulnerability management processes. Standard mitigations such as least-privilege enforcement, exploit protection, and application allowlisting are recommended to reduce impact should exploitation attempts emerge.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-060
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free