Mozilla Mozilla

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Mozilla product.

RSS Feeds for Mozilla security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Mozilla Sorted by Most Security Vulnerabilities since 2018

Mozilla Firefox2465 vulnerabilities
Open source web browser

Mozilla Thunderbird1685 vulnerabilities
Email client

Mozilla SeaMonkey286 vulnerabilities
Browser, email and newsgroup client

Mozilla Thunderbird Esr217 vulnerabilities

Mozilla Focus24 vulnerabilities

Mozilla Firefox Mobile21 vulnerabilities

Mozilla Firefox Focus17 vulnerabilities

Mozilla9 vulnerabilities

Mozilla Nss8 vulnerabilities

Mozilla Firefox Os5 vulnerabilities

Mozilla Vpn4 vulnerabilities

Mozilla Nunjucks1 vulnerability

Mozilla Zamboni1 vulnerability

Recent Mozilla Security Advisories

Advisory Title Published
mfsa2026-96 Security Vulnerabilities fixed in Thunderbird 153.3 mfsa2026-96 September 16, 2026
mfsa2026-92 Security Vulnerabilities fixed in Firefox ESR 140.16 mfsa2026-92 September 15, 2026
mfsa2026-95 Security Vulnerabilities fixed in Thunderbird 140.16 mfsa2026-95 September 15, 2026
mfsa2026-90 Security Vulnerabilities fixed in Firefox 156 mfsa2026-90 September 15, 2026
mfsa2026-93 Security Vulnerabilities fixed in Firefox ESR 153.3 mfsa2026-93 September 15, 2026
mfsa2026-91 Security Vulnerabilities fixed in Firefox ESR 115.41 mfsa2026-91 September 15, 2026
mfsa2026-94 Security Vulnerabilities fixed in Thunderbird 156 mfsa2026-94 September 15, 2026
mfsa2026-89 Security Vulnerabilities fixed in Firefox for iOS 155.1 mfsa2026-89 September 8, 2026
mfsa2026-85 Security Vulnerabilities fixed in Firefox ESR 153.2 mfsa2026-85 September 1, 2026
mfsa2026-88 Security Vulnerabilities fixed in Thunderbird 153.2 mfsa2026-88 September 1, 2026

Known Exploited Mozilla Vulnerabilities

The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Mozilla Multiple Products Remote Code Execution Vulnerability Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.
CVE-2010-3765 Exploit Probability: 83.2%
October 6, 2025
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-9680 Exploit Probability: 23.2%
October 15, 2024
Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2016-9079 Exploit Probability: 87.4%
June 22, 2023
Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-4495 Exploit Probability: 71.3%
May 25, 2022
Mozilla Firefox and Thunderbird Type Confusion Vulnerability Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2019-11707 Exploit Probability: 37.7%
May 23, 2022
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2019-11708 Exploit Probability: 55.9%
May 23, 2022
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site.
CVE-2013-1690 Exploit Probability: 69.0%
March 28, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2022-26486 Exploit Probability: 2.3%
March 7, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
CVE-2022-26485 Exploit Probability: 14.3%
March 7, 2022
Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2013-1675 Exploit Probability: 6.7%
March 3, 2022
Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVE-2020-6819 Exploit Probability: 3.0%
November 3, 2021
Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
CVE-2020-6820 Exploit Probability: 7.1%
November 3, 2021
Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1
CVE-2019-17026 Exploit Probability: 46.3%
November 3, 2021

Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 513 vulnerabilities in Mozilla with an average score of 7.8 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. That is, 304 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.38.




Year Vulnerabilities Average Score
2026 513 7.85
2025 209 7.46
2024 204 7.10
2023 202 7.24
2022 188 7.42
2021 158 7.12
2020 184 7.25
2019 152 7.53
2018 345 7.65

It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-92240 Sep 15, 2026
Thunderbird <140.16 OOB Read in IMAP Parser via * ID Response A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Thunderbird
CVE-2026-92239 Sep 15, 2026
OOB buffer read in Thunderbird IMAP parser before 140.16 A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Thunderbird
CVE-2026-92238 Sep 15, 2026
Memory Safety Violation via Malformed Mail Header in Thunderbird <140.16 A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Thunderbird
CVE-2026-92079 Sep 15, 2026
Widget: Win32 Mitigation Bypass in Firefox 156 ESR 153.3 Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92078 Sep 15, 2026
Firefox Denial-of-service in Security component before 156 Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92077 Sep 15, 2026
DoS in Firefox SVG component before v156 Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92076 Sep 15, 2026
Firefox 156+ Boundary Condition Flaw in Networking Component Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92075 Sep 15, 2026
Mitigation bypass in Firefox Networking component pre-156/ESR153.3 Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92074 Sep 15, 2026
Mitigation Bypass in Firefox Popup Blocker (before 156) Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92073 Sep 15, 2026
Firefox: PrivEsc via Enterprise Policies pre-156/153.3 Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92072 Sep 15, 2026
Firefox SB boundary issue fixed in v156/ESR153.3 Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92071 Sep 15, 2026
Firefox Sandbox Escape via Widget Boundaries fixed in v156/ESR 153.3 Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92070 Sep 15, 2026
Firefox Info Disclosure in Networking Comp (before 156/ESR 153.3) Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92069 Sep 15, 2026
Firefox Navigation Component Spoofing (fixed in 156) Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92068 Sep 15, 2026
Site isolation flaw in Firefox Reader Mode (pre156/ESR153.3) Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92067 Sep 15, 2026
Use-after-free in the Widget: Gtk component Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92066 Sep 15, 2026
Sandbox escape in the Profile Backup component Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92065 Sep 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92064 Sep 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92063 Sep 15, 2026
Denial-of-service in the Audio/Video component Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92062 Sep 15, 2026
Privilege escalation in the Session Restore component Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92061 Sep 15, 2026
Incorrect boundary conditions in the Security: Process Sandboxing component Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92060 Sep 15, 2026
Use-after-free in the Internationalization component Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92059 Sep 15, 2026
Incorrect boundary conditions in the DOM: Editor component Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92058 Sep 15, 2026
Use-after-free in the Graphics component Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92057 Sep 15, 2026
Mitigation bypass in the Enterprise Policies component Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92056 Sep 15, 2026
Use-after-free in the Graphics: Text component Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92055 Sep 15, 2026
Privilege escalation in the DevTools component Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92054 Sep 15, 2026
Privilege escalation in the Memory component Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92053 Sep 15, 2026
Privilege escalation in the Graphics: CanvasWebGL component Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92052 Sep 15, 2026
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92051 Sep 15, 2026
Spoofing issue due to invalid pointer in the Graphics component Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92050 Sep 15, 2026
Sandbox escape due to race condition in the XPConnect component Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92049 Sep 15, 2026
Use-after-free in the Widget: Win32 component Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92048 Sep 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92047 Sep 15, 2026
Privilege escalation in the Crash Reporting component Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92046 Sep 15, 2026
Use-after-free in the Graphics component Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92045 Sep 15, 2026
Sandbox escape due to incorrect boundary conditions in the WebRTC component Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92044 Sep 15, 2026
Information disclosure in the Networking: HTTP component Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92043 Sep 15, 2026
Privilege escalation due to incorrect boundary conditions in the Audio/Video component Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92042 Sep 15, 2026
Race condition in the DOM: Content Processes component Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92041 Sep 15, 2026
Mitigation bypass in the DOM: Networking component Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92040 Sep 15, 2026
Use-after-free in the JavaScript: WebAssembly component Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92039 Sep 15, 2026
Mitigation bypass in the DOM: Notifications component Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92038 Sep 15, 2026
Mitigation bypass in the Remote Settings Client component Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92037 Sep 15, 2026
Incorrect boundary conditions in the DOM: Animation component Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92036 Sep 15, 2026
Incorrect boundary conditions in the Networking: HTTP component Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92035 Sep 15, 2026
Sandbox escape due to incorrect boundary conditions in the Graphics component Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox
Thunderbird
CVE-2026-92034 Sep 15, 2026
Site isolation issue in the Graphics component Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Firefox
Thunderbird
CVE-2026-92033 Sep 15, 2026
Privilege escalation in Firefox for Android Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Firefox
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.