Mozilla Firefox Open source web browser
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Mozilla Firefox.
Recent Mozilla Firefox Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-90 | Security Vulnerabilities fixed in Firefox 156 mfsa2026-90 | September 15, 2026 |
| mfsa2026-92 | Security Vulnerabilities fixed in Firefox ESR 140.16 mfsa2026-92 | September 15, 2026 |
| mfsa2026-91 | Security Vulnerabilities fixed in Firefox ESR 115.41 mfsa2026-91 | September 15, 2026 |
| mfsa2026-93 | Security Vulnerabilities fixed in Firefox ESR 153.3 mfsa2026-93 | September 15, 2026 |
| mfsa2026-89 | Security Vulnerabilities fixed in Firefox for iOS 155.1 mfsa2026-89 | September 8, 2026 |
| mfsa2026-82 | Security Vulnerabilities fixed in Firefox 155 mfsa2026-82 | September 1, 2026 |
| mfsa2026-83 | Security Vulnerabilities fixed in Firefox ESR 115.40 mfsa2026-83 | September 1, 2026 |
| mfsa2026-84 | Security Vulnerabilities fixed in Firefox ESR 140.15 mfsa2026-84 | September 1, 2026 |
| mfsa2026-85 | Security Vulnerabilities fixed in Firefox ESR 153.2 mfsa2026-85 | September 1, 2026 |
| mfsa2026-81 | Security Vulnerabilities fixed in Firefox for iOS 155.0 mfsa2026-81 | August 31, 2026 |
Known Exploited Mozilla Firefox Vulnerabilities
The following Mozilla Firefox vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 23.2% |
October 15, 2024 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 71.4% |
May 25, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 14.3% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
The vulnerability CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Mozilla Firefox vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
EOL Dates
Ensure that you are using a supported version of Mozilla Firefox. Here are some end of life, and end of support dates for Mozilla Firefox.
| Release | EOL Date | Status |
|---|---|---|
| 156 | - |
Active
|
| 155 | September 15, 2026 |
EOL
Mozilla Firefox 155 became EOL in 2026. |
| 154 | September 1, 2026 |
EOL
Mozilla Firefox 154 became EOL in 2026. |
| 153 | - |
Active
|
| 152 | July 21, 2026 |
EOL
Mozilla Firefox 152 became EOL in 2026. |
| 151 | June 16, 2026 |
EOL
Mozilla Firefox 151 became EOL in 2026. |
| 150 | May 18, 2026 |
EOL
Mozilla Firefox 150 became EOL in 2026. |
| 149 | April 21, 2026 |
EOL
Mozilla Firefox 149 became EOL in 2026. |
| 148 | March 24, 2026 |
EOL
Mozilla Firefox 148 became EOL in 2026. |
| 147 | February 24, 2026 |
EOL
Mozilla Firefox 147 became EOL in 2026. |
| 146 | January 13, 2026 |
EOL
Mozilla Firefox 146 became EOL in 2026. |
| 145 | December 9, 2025 |
EOL
Mozilla Firefox 145 became EOL in 2025. |
| 144 | November 11, 2025 |
EOL
Mozilla Firefox 144 became EOL in 2025. |
| 143 | October 14, 2025 |
EOL
Mozilla Firefox 143 became EOL in 2025. |
| 142 | September 16, 2025 |
EOL
Mozilla Firefox 142 became EOL in 2025. |
| 141 | August 19, 2025 |
EOL
Mozilla Firefox 141 became EOL in 2025. |
| 140 | September 29, 2026 |
EOL This Year
Mozilla Firefox 140 will become EOL this year, in September 2026. |
| 139 | June 24, 2025 |
EOL
Mozilla Firefox 139 became EOL in 2025. |
| 138 | May 27, 2025 |
EOL
Mozilla Firefox 138 became EOL in 2025. |
| 137 | April 29, 2025 |
EOL
Mozilla Firefox 137 became EOL in 2025. |
By the Year
In 2026 there have been 496 vulnerabilities in Mozilla Firefox with an average score of 7.8 out of ten. Last year, in 2025 Firefox had 189 security vulnerabilities published. That is, 307 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.30.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 496 | 7.85 |
| 2025 | 189 | 7.54 |
| 2024 | 190 | 7.15 |
| 2023 | 180 | 7.38 |
| 2022 | 159 | 7.44 |
| 2021 | 123 | 7.13 |
| 2020 | 148 | 7.27 |
| 2019 | 121 | 7.44 |
| 2018 | 312 | 7.82 |
It may take a day or so for new Firefox vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Firefox Security Vulnerabilities
Widget: Win32 Mitigation Bypass in Firefox 156 ESR 153.3
CVE-2026-92079
- September 15, 2026
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox Denial-of-service in Security component before 156
CVE-2026-92078
- September 15, 2026
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
DoS in Firefox SVG component before v156
CVE-2026-92077
- September 15, 2026
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox 156+ Boundary Condition Flaw in Networking Component
CVE-2026-92076
- September 15, 2026
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Mitigation bypass in Firefox Networking component pre-156/ESR153.3
CVE-2026-92075
- September 15, 2026
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Mitigation Bypass in Firefox Popup Blocker (before 156)
CVE-2026-92074
- September 15, 2026
Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox: PrivEsc via Enterprise Policies pre-156/153.3
CVE-2026-92073
8.8 - High
- September 15, 2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Firefox SB boundary issue fixed in v156/ESR153.3
CVE-2026-92072
- September 15, 2026
Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox Sandbox Escape via Widget Boundaries fixed in v156/ESR 153.3
CVE-2026-92071
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox Info Disclosure in Networking Comp (before 156/ESR 153.3)
CVE-2026-92070
- September 15, 2026
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Firefox Navigation Component Spoofing (fixed in 156)
CVE-2026-92069
- September 15, 2026
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Site isolation flaw in Firefox Reader Mode (pre156/ESR153.3)
CVE-2026-92068
- September 15, 2026
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Use-after-free in the Widget: Gtk component
CVE-2026-92067
- September 15, 2026
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Sandbox escape in the Profile Backup component
CVE-2026-92066
- September 15, 2026
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92065
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92064
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Denial-of-service in the Audio/Video component
CVE-2026-92063
- September 15, 2026
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Privilege escalation in the Session Restore component
CVE-2026-92062
8.8 - High
- September 15, 2026
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Incorrect boundary conditions in the Security: Process Sandboxing component
CVE-2026-92061
- September 15, 2026
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Use-after-free in the Internationalization component
CVE-2026-92060
- September 15, 2026
Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Incorrect boundary conditions in the DOM: Editor component
CVE-2026-92059
- September 15, 2026
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Use-after-free in the Graphics component
CVE-2026-92058
- September 15, 2026
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Mitigation bypass in the Enterprise Policies component
CVE-2026-92057
- September 15, 2026
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Use-after-free in the Graphics: Text component
CVE-2026-92056
- September 15, 2026
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Privilege escalation in the DevTools component
CVE-2026-92055
8.8 - High
- September 15, 2026
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Privilege escalation in the Memory component
CVE-2026-92054
8.8 - High
- September 15, 2026
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-92053
8.8 - High
- September 15, 2026
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
CVE-2026-92052
8.8 - High
- September 15, 2026
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Use of Uninitialized Variable
Spoofing issue due to invalid pointer in the Graphics component
CVE-2026-92051
- September 15, 2026
Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Sandbox escape due to race condition in the XPConnect component
CVE-2026-92050
- September 15, 2026
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Use-after-free in the Widget: Win32 component
CVE-2026-92049
- September 15, 2026
Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92048
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Privilege escalation in the Crash Reporting component
CVE-2026-92047
8.8 - High
- September 15, 2026
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Use-after-free in the Graphics component
CVE-2026-92046
- September 15, 2026
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVE-2026-92045
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Information disclosure in the Networking: HTTP component
CVE-2026-92044
- September 15, 2026
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Privilege escalation due to incorrect boundary conditions in the Audio/Video component
CVE-2026-92043
8.8 - High
- September 15, 2026
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Classic Buffer Overflow
Race condition in the DOM: Content Processes component
CVE-2026-92042
- September 15, 2026
Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Mitigation bypass in the DOM: Networking component
CVE-2026-92041
- September 15, 2026
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Use-after-free in the JavaScript: WebAssembly component
CVE-2026-92040
- September 15, 2026
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Mitigation bypass in the DOM: Notifications component
CVE-2026-92039
- September 15, 2026
Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Mitigation bypass in the Remote Settings Client component
CVE-2026-92038
- September 15, 2026
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Incorrect boundary conditions in the DOM: Animation component
CVE-2026-92037
- September 15, 2026
Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Incorrect boundary conditions in the Networking: HTTP component
CVE-2026-92036
- September 15, 2026
Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Sandbox escape due to incorrect boundary conditions in the Graphics component
CVE-2026-92035
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Site isolation issue in the Graphics component
CVE-2026-92034
- September 15, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Privilege escalation in Firefox for Android
CVE-2026-92033
8.8 - High
- September 15, 2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Improper Privilege Management
Sandbox escape due to invalid pointer in the Graphics component
CVE-2026-92032
- September 15, 2026
Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Information disclosure in the Graphics: ImageLib component
CVE-2026-92031
- September 15, 2026
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
CVE-2026-92030
- September 15, 2026
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Mozilla Firefox or by Mozilla? Click the Watch button to subscribe.