Mozilla
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Mozilla product.
RSS Feeds for Mozilla security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Mozilla Sorted by Most Security Vulnerabilities since 2018
Recent Mozilla Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-96 | Security Vulnerabilities fixed in Thunderbird 153.3 mfsa2026-96 | September 16, 2026 |
| mfsa2026-92 | Security Vulnerabilities fixed in Firefox ESR 140.16 mfsa2026-92 | September 15, 2026 |
| mfsa2026-95 | Security Vulnerabilities fixed in Thunderbird 140.16 mfsa2026-95 | September 15, 2026 |
| mfsa2026-90 | Security Vulnerabilities fixed in Firefox 156 mfsa2026-90 | September 15, 2026 |
| mfsa2026-93 | Security Vulnerabilities fixed in Firefox ESR 153.3 mfsa2026-93 | September 15, 2026 |
| mfsa2026-91 | Security Vulnerabilities fixed in Firefox ESR 115.41 mfsa2026-91 | September 15, 2026 |
| mfsa2026-94 | Security Vulnerabilities fixed in Thunderbird 156 mfsa2026-94 | September 15, 2026 |
| mfsa2026-89 | Security Vulnerabilities fixed in Firefox for iOS 155.1 mfsa2026-89 | September 8, 2026 |
| mfsa2026-85 | Security Vulnerabilities fixed in Firefox ESR 153.2 mfsa2026-85 | September 1, 2026 |
| mfsa2026-88 | Security Vulnerabilities fixed in Thunderbird 153.2 mfsa2026-88 | September 1, 2026 |
Known Exploited Mozilla Vulnerabilities
The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Multiple Products Remote Code Execution Vulnerability |
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. CVE-2010-3765 Exploit Probability: 83.2% |
October 6, 2025 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 23.2% |
October 15, 2024 |
| Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability |
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. CVE-2016-9079 Exploit Probability: 87.4% |
June 22, 2023 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 71.3% |
May 25, 2022 |
| Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. CVE-2019-11707 Exploit Probability: 37.7% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability |
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. CVE-2019-11708 Exploit Probability: 55.9% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability |
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site. CVE-2013-1690 Exploit Probability: 69.0% |
March 28, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 14.3% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
| Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability |
A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6819 Exploit Probability: 3.0% |
November 3, 2021 |
| Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability |
A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6820 Exploit Probability: 7.1% |
November 3, 2021 |
| Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability |
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1 CVE-2019-17026 Exploit Probability: 46.3% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 513 vulnerabilities in Mozilla with an average score of 7.8 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. That is, 304 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 513 | 7.85 |
| 2025 | 209 | 7.46 |
| 2024 | 204 | 7.10 |
| 2023 | 202 | 7.24 |
| 2022 | 188 | 7.42 |
| 2021 | 158 | 7.12 |
| 2020 | 184 | 7.25 |
| 2019 | 152 | 7.53 |
| 2018 | 345 | 7.65 |
It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-92240 | Sep 15, 2026 |
Thunderbird <140.16 OOB Read in IMAP Parser via * ID ResponseA malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
|
| CVE-2026-92239 | Sep 15, 2026 |
OOB buffer read in Thunderbird IMAP parser before 140.16A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
|
| CVE-2026-92238 | Sep 15, 2026 |
Memory Safety Violation via Malformed Mail Header in Thunderbird <140.16A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
|
| CVE-2026-92079 | Sep 15, 2026 |
Widget: Win32 Mitigation Bypass in Firefox 156 ESR 153.3Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92078 | Sep 15, 2026 |
Firefox Denial-of-service in Security component before 156Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92077 | Sep 15, 2026 |
DoS in Firefox SVG component before v156Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92076 | Sep 15, 2026 |
Firefox 156+ Boundary Condition Flaw in Networking ComponentIncorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92075 | Sep 15, 2026 |
Mitigation bypass in Firefox Networking component pre-156/ESR153.3Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92074 | Sep 15, 2026 |
Mitigation Bypass in Firefox Popup Blocker (before 156)Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92073 | Sep 15, 2026 |
Firefox: PrivEsc via Enterprise Policies pre-156/153.3Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92072 | Sep 15, 2026 |
Firefox SB boundary issue fixed in v156/ESR153.3Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92071 | Sep 15, 2026 |
Firefox Sandbox Escape via Widget Boundaries fixed in v156/ESR 153.3Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92070 | Sep 15, 2026 |
Firefox Info Disclosure in Networking Comp (before 156/ESR 153.3)Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92069 | Sep 15, 2026 |
Firefox Navigation Component Spoofing (fixed in 156)Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92068 | Sep 15, 2026 |
Site isolation flaw in Firefox Reader Mode (pre156/ESR153.3)Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92067 | Sep 15, 2026 |
Use-after-free in the Widget: Gtk componentUse-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92066 | Sep 15, 2026 |
Sandbox escape in the Profile Backup componentSandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92065 | Sep 15, 2026 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 componentSandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92064 | Sep 15, 2026 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 componentSandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92063 | Sep 15, 2026 |
Denial-of-service in the Audio/Video componentDenial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92062 | Sep 15, 2026 |
Privilege escalation in the Session Restore componentPrivilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92061 | Sep 15, 2026 |
Incorrect boundary conditions in the Security: Process Sandboxing componentIncorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92060 | Sep 15, 2026 |
Use-after-free in the Internationalization componentUse-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92059 | Sep 15, 2026 |
Incorrect boundary conditions in the DOM: Editor componentIncorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92058 | Sep 15, 2026 |
Use-after-free in the Graphics componentUse-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92057 | Sep 15, 2026 |
Mitigation bypass in the Enterprise Policies componentMitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92056 | Sep 15, 2026 |
Use-after-free in the Graphics: Text componentUse-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92055 | Sep 15, 2026 |
Privilege escalation in the DevTools componentPrivilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92054 | Sep 15, 2026 |
Privilege escalation in the Memory componentPrivilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92053 | Sep 15, 2026 |
Privilege escalation in the Graphics: CanvasWebGL componentPrivilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92052 | Sep 15, 2026 |
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL componentPrivilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92051 | Sep 15, 2026 |
Spoofing issue due to invalid pointer in the Graphics componentSpoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92050 | Sep 15, 2026 |
Sandbox escape due to race condition in the XPConnect componentSandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92049 | Sep 15, 2026 |
Use-after-free in the Widget: Win32 componentUse-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92048 | Sep 15, 2026 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 componentSandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92047 | Sep 15, 2026 |
Privilege escalation in the Crash Reporting componentPrivilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92046 | Sep 15, 2026 |
Use-after-free in the Graphics componentUse-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92045 | Sep 15, 2026 |
Sandbox escape due to incorrect boundary conditions in the WebRTC componentSandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92044 | Sep 15, 2026 |
Information disclosure in the Networking: HTTP componentInformation disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92043 | Sep 15, 2026 |
Privilege escalation due to incorrect boundary conditions in the Audio/Video componentPrivilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92042 | Sep 15, 2026 |
Race condition in the DOM: Content Processes componentRace condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92041 | Sep 15, 2026 |
Mitigation bypass in the DOM: Networking componentMitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92040 | Sep 15, 2026 |
Use-after-free in the JavaScript: WebAssembly componentUse-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92039 | Sep 15, 2026 |
Mitigation bypass in the DOM: Notifications componentMitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92038 | Sep 15, 2026 |
Mitigation bypass in the Remote Settings Client componentMitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92037 | Sep 15, 2026 |
Incorrect boundary conditions in the DOM: Animation componentIncorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92036 | Sep 15, 2026 |
Incorrect boundary conditions in the Networking: HTTP componentIncorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92035 | Sep 15, 2026 |
Sandbox escape due to incorrect boundary conditions in the Graphics componentSandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
|
| CVE-2026-92034 | Sep 15, 2026 |
Site isolation issue in the Graphics componentSite isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
|
| CVE-2026-92033 | Sep 15, 2026 |
Privilege escalation in Firefox for AndroidPrivilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. |
|