Mozilla
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Mozilla product.
RSS Feeds for Mozilla security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Mozilla products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Mozilla Sorted by Most Security Vulnerabilities since 2018
Recent Mozilla Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-45 | Security Vulnerabilities fixed in Firefox 150.0.3 mfsa2026-45 | May 12, 2026 |
| mfsa2026-44 | Security Vulnerabilities fixed in Thunderbird 140.10.2 mfsa2026-44 | May 8, 2026 |
| mfsa2026-43 | Security Vulnerabilities fixed in Thunderbird 150.0.2 mfsa2026-43 | May 8, 2026 |
| mfsa2026-40 | Security Vulnerabilities fixed in Firefox 150.0.2 mfsa2026-40 | May 7, 2026 |
| mfsa2026-41 | Security Vulnerabilities fixed in Firefox ESR 140.10.2 mfsa2026-41 | May 7, 2026 |
| mfsa2026-42 | Security Vulnerabilities fixed in Firefox ESR 115.35.2 mfsa2026-42 | May 7, 2026 |
| mfsa2026-39 | Security Vulnerabilities fixed in Thunderbird 140.10.1 mfsa2026-39 | April 30, 2026 |
| mfsa2026-38 | Security Vulnerabilities fixed in Thunderbird 150.0.1 mfsa2026-38 | April 30, 2026 |
| mfsa2026-35 | Security Vulnerabilities fixed in Firefox 150.0.1 mfsa2026-35 | April 28, 2026 |
| mfsa2026-37 | Security Vulnerabilities fixed in Firefox ESR 115.35.1 mfsa2026-37 | April 28, 2026 |
Known Exploited Mozilla Vulnerabilities
The following Mozilla vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Multiple Products Remote Code Execution Vulnerability |
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. CVE-2010-3765 Exploit Probability: 86.6% |
October 6, 2025 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 30.8% |
October 15, 2024 |
| Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability |
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. CVE-2016-9079 Exploit Probability: 84.8% |
June 22, 2023 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 71.6% |
May 25, 2022 |
| Mozilla Firefox and Thunderbird Type Confusion Vulnerability |
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. CVE-2019-11707 Exploit Probability: 84.3% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability |
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. CVE-2019-11708 Exploit Probability: 68.1% |
May 23, 2022 |
| Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability |
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service or possibly execute arbitrary code via a crafted web site. CVE-2013-1690 Exploit Probability: 47.1% |
March 28, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 5.5% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 7.2% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 7.9% |
March 3, 2022 |
| Mozilla Firefox 74 and Firefox ESR 68.6 nsDocShell vulnerability |
A race condition can cause a use-after-free when running the nsDocShell destructor. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6819 Exploit Probability: 0.4% |
November 3, 2021 |
| Mozilla Firefox 74 and Firefox ESR 68.6 ReadableStream vulnerability |
A race condition can cause a use-after-free when handling a ReadableStream. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1. CVE-2020-6820 Exploit Probability: 3.1% |
November 3, 2021 |
| Mozilla Firefox IonMonkey JIT compiler Type Confusion Vulnerability |
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1 CVE-2019-17026 Exploit Probability: 59.1% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 5 known exploited Mozilla vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 186 vulnerabilities in Mozilla with an average score of 8.2 out of ten. Last year, in 2025 Mozilla had 209 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Mozilla in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.73.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 186 | 8.19 |
| 2025 | 209 | 7.46 |
| 2024 | 204 | 7.10 |
| 2023 | 202 | 7.24 |
| 2022 | 188 | 7.42 |
| 2021 | 158 | 7.12 |
| 2020 | 184 | 7.25 |
| 2019 | 152 | 7.53 |
| 2018 | 345 | 7.65 |
It may take a day or so for new Mozilla vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-8401 | May 12, 2026 |
Firefox 150.0.3 Sandbox Escape in Profile Backup (Fixed)Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3. |
|
| CVE-2026-8391 | May 12, 2026 |
JavaScript Engine flaw in Firefox 150.0.3 (fixed)Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3. |
|
| CVE-2026-8390 | May 12, 2026 |
Firefox WebAssembly Component UAF (pre-150.0.3)Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. |
|
| CVE-2026-8389 | May 12, 2026 |
Firefox JIT Miscompilation in JS Engine, Fixed in 150.0.3JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. |
|
| CVE-2026-8388 | May 12, 2026 |
Firefox 150 JIT Boundary Condition Vulnerability in JS EngineIncorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. |
|
| CVE-2026-8094 | May 07, 2026 |
Firefox ESR 140.10.2 WebRTC VulnerabilityOther issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. |
|
| CVE-2026-8093 | May 07, 2026 |
Firefox 150.0.1 Memcor bugs may allow arbitrary code executionMemory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2. |
|
| CVE-2026-8092 | May 07, 2026 |
Firefox 115.35.1/140.10.1/150.0.1 Memory Safety BugMemory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2. |
|
| CVE-2026-8091 | May 07, 2026 |
Firefox ESR AV Playback boundary flaw before 140.10.2Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2. |
|
| CVE-2026-8090 | May 07, 2026 |
Use-after-free in Firefox DOM Networking pre-150.0.2Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2. |
|
| CVE-2026-7321 | Apr 28, 2026 |
Firefox Sandbox Escape in WebRTC Networking before ESR 140.10.1Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1. |
|
| CVE-2026-7324 | Apr 28, 2026 |
Memory safety bugs in Firefox 150.0.0 (fixed 150.0.1)Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1. |
|
| CVE-2026-7323 | Apr 28, 2026 |
Memory Safety Bug in Firefox ESR 140.10.0 & Thunderbird 140.10.0Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. |
|
| CVE-2026-7322 | Apr 28, 2026 |
Memory safety bugs in Firefox ESR 115.35.0/140.10.0 & 150.0.0 (fixed 150.0.1)Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. |
|
| CVE-2026-7320 | Apr 28, 2026 |
Firefox Audio/Video Boundary Bug Info Disclosure (fixed in 150.0.1)Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. |
|
| CVE-2026-6786 | Apr 21, 2026 |
Firefox 149 / ESR 140.9 Memory Safety Bugs (Arbitrary Code Exec)Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6785 | Apr 21, 2026 |
Mozilla Firefox Memory Safety Bug (ESR 115.34, 115.35, ESR 140.9/140.10, 149)Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6784 | Apr 21, 2026 |
Memory Safety Bugs in Firefox 149 & Thunderbird 149Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6782 | Apr 21, 2026 |
Info Disclosure via Firefox IP Protection ComponentInformation disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6783 | Apr 21, 2026 |
Firefox 150 AV Playback CVE20266783 Integer OverflowIncorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6781 | Apr 21, 2026 |
DoS in Firefox AV Playback Component (CVE-2026-6781)Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6780 | Apr 21, 2026 |
Firefox A/V Playback DoS VulnerabilityDenial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6779 | Apr 21, 2026 |
Mozilla Firefox JS Engine CVE-2026-6779 (Other issue)Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6778 | Apr 21, 2026 |
Firefox 150 - Invalid Pointer in Audio/Video PlaybackInvalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6777 | Apr 21, 2026 |
CVE-2026-6777: Firefox DNS Component VulnerabilityOther issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6776 | Apr 21, 2026 |
Firefox <150 WebRTC Networking boundary condition flaw (CVE-2026-6776)Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6775 | Apr 21, 2026 |
Firefox WebRTC Improper Boundary Check (CVE-2026-6775)Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6774 | Apr 21, 2026 |
DOM Mitigation Bypass in Firefox Security ComponentMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6772 | Apr 21, 2026 |
Firefox NSS Libraries Boundary Cond. before 150Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6773 | Apr 21, 2026 |
Firefox WebGPU Integer Overflow DoSDenial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6771 | Apr 21, 2026 |
Firefox 150 DOM Mitigation Bypass in Security ComponentMitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6770 | Apr 21, 2026 |
IndexedDB flaw in Firefox <=150 (ESR 140.10)Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6769 | Apr 21, 2026 |
Priv Escalation in Firefox Debugger (before 150)Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6768 | Apr 21, 2026 |
CVE-2026-6768: Mitigation Bypass in Firefox Cookies HandlingMitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6767 | Apr 21, 2026 |
NSS Lib Other Issue (Fixed in Firefox 150/ESR 115.35)Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6766 | Apr 21, 2026 |
Firefox NSS boundary overflow (before 150/140.10)Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6765 | Apr 21, 2026 |
Firefox Autofill Info Disclosure before 150Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6764 | Apr 21, 2026 |
Firefox DOM Boundary Condition Flaw in Device Interfaces (fixed in v150)Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6763 | Apr 21, 2026 |
Firefox File Handling Mitigation Bypass (Before 150/ESR 140.10)Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6762 | Apr 21, 2026 |
Firefox DOM Spoofing Vulnerability (pre-150) Core & HTMLSpoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6761 | Apr 21, 2026 |
Firefox 150 PrivEsc via Networking ComponentPrivilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6760 | Apr 21, 2026 |
Firefox Networking Cookies Mitigation Bypass CVE-2026-6760Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6759 | Apr 21, 2026 |
Use-after-free in Firefox Widget Cocoa (150)Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6758 | Apr 21, 2026 |
Use-after-free: WebAssembly Component in FirefoxUse-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6757 | Apr 21, 2026 |
Firefox WebAsm Null Pointer Bug Before v150 (CVE-2026-6757)Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6756 | Apr 21, 2026 |
Firefox for Android Mitigation BypassMitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. |
|
| CVE-2026-6754 | Apr 21, 2026 |
UAF in JavaScript Engine, fixed in Firefox 150/ESR 115.35/140.10Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6755 | Apr 21, 2026 |
Mozilla Firefox postMessage DOM Mitigation Bypass (CVE20266755)Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
| CVE-2026-6753 | Apr 21, 2026 |
Firefox WebRTC Boundary Condition Vulnerability (fixed in 150/ESR 140.10)Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
| CVE-2026-6752 | Apr 21, 2026 |
Firefox WebRTC Boundary Condition Flaw (before v150 / ESR 115.35)Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|