Firefox Mozilla Firefox Open source web browser

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mozilla Firefox.

Recent Mozilla Firefox Security Advisories

Advisory Title Published
mfsa2026-49 Security Vulnerabilities fixed in Firefox for iOS 151.0 mfsa2026-49 May 19, 2026
mfsa2026-48 Security Vulnerabilities fixed in Firefox ESR 140.11 mfsa2026-48 May 19, 2026
mfsa2026-47 Security Vulnerabilities fixed in Firefox ESR 115.36 mfsa2026-47 May 19, 2026
mfsa2026-46 Security Vulnerabilities fixed in Firefox 151 mfsa2026-46 May 19, 2026
mfsa2026-45 Security Vulnerabilities fixed in Firefox 150.0.3 mfsa2026-45 May 12, 2026
mfsa2026-42 Security Vulnerabilities fixed in Firefox ESR 115.35.2 mfsa2026-42 May 7, 2026
mfsa2026-41 Security Vulnerabilities fixed in Firefox ESR 140.10.2 mfsa2026-41 May 7, 2026
mfsa2026-40 Security Vulnerabilities fixed in Firefox 150.0.2 mfsa2026-40 May 7, 2026
mfsa2026-37 Security Vulnerabilities fixed in Firefox ESR 115.35.1 mfsa2026-37 April 28, 2026
mfsa2026-35 Security Vulnerabilities fixed in Firefox 150.0.1 mfsa2026-35 April 28, 2026

Known Exploited Mozilla Firefox Vulnerabilities

The following Mozilla Firefox vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-9680 Exploit Probability: 35.0%
October 15, 2024
Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-4495 Exploit Probability: 71.6%
May 25, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2022-26486 Exploit Probability: 5.5%
March 7, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
CVE-2022-26485 Exploit Probability: 7.2%
March 7, 2022
Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2013-1675 Exploit Probability: 7.9%
March 3, 2022

2 known exploited Mozilla Firefox vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

EOL Dates

Ensure that you are using a supported version of Mozilla Firefox. Here are some end of life, and end of support dates for Mozilla Firefox.

Release EOL Date Status
151 -
Active

150 May 18, 2026
EOL

Mozilla Firefox 150 became EOL in 2026.

149 April 21, 2026
EOL

Mozilla Firefox 149 became EOL in 2026.

148 March 24, 2026
EOL

Mozilla Firefox 148 became EOL in 2026.

147 February 24, 2026
EOL

Mozilla Firefox 147 became EOL in 2026.

146 January 13, 2026
EOL

Mozilla Firefox 146 became EOL in 2026.

145 December 9, 2025
EOL

Mozilla Firefox 145 became EOL in 2025.

144 November 11, 2025
EOL

Mozilla Firefox 144 became EOL in 2025.

143 October 14, 2025
EOL

Mozilla Firefox 143 became EOL in 2025.

142 September 16, 2025
EOL

Mozilla Firefox 142 became EOL in 2025.

141 August 19, 2025
EOL

Mozilla Firefox 141 became EOL in 2025.

140 September 16, 2026
EOL This Year

Mozilla Firefox 140 will become EOL this year, in September 2026.

139 June 24, 2025
EOL

Mozilla Firefox 139 became EOL in 2025.

138 May 27, 2025
EOL

Mozilla Firefox 138 became EOL in 2025.

137 April 29, 2025
EOL

Mozilla Firefox 137 became EOL in 2025.

136 April 1, 2025
EOL

Mozilla Firefox 136 became EOL in 2025.

135 March 4, 2025
EOL

Mozilla Firefox 135 became EOL in 2025.

134 February 4, 2025
EOL

Mozilla Firefox 134 became EOL in 2025.

133 January 7, 2025
EOL

Mozilla Firefox 133 became EOL in 2025.

132 November 26, 2024
EOL

Mozilla Firefox 132 became EOL in 2024.

By the Year

In 2026 there have been 213 vulnerabilities in Mozilla Firefox with an average score of 8.2 out of ten. Last year, in 2025 Firefox had 189 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.68.




Year Vulnerabilities Average Score
2026 213 8.22
2025 189 7.54
2024 190 7.15
2023 180 7.38
2022 159 7.44
2021 123 7.13
2020 148 7.27
2019 121 7.44
2018 312 7.82

It may take a day or so for new Firefox vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Firefox Security Vulnerabilities

Firefox iOS 151.0 Reader Mode Local Server SSRF
CVE-2026-8706 6.5 - Medium - May 19, 2026

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.

Missing Authentication for Critical Function

Mozilla Firefox ESR 115.35/140.10/150 Mem Safety Bug (CVE-2026-8975)
CVE-2026-8975 8.8 - High - May 19, 2026

Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Buffer Overflow

Firefox Memory Safety Bugs 140.10/150: Arbitrary Code Exec Fix in 151
CVE-2026-8974 8.8 - High - May 19, 2026

Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Buffer Overflow

Mem Saf Bugs in Mozilla Firefox 150
CVE-2026-8973 8.8 - High - May 19, 2026

Memory safety bugs present in Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Buffer Overflow

Firefox WebRTC Audio/Video PE Vulnerability
CVE-2026-8972 8.8 - High - May 19, 2026

Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Improper Privilege Management

CVE-2026-8971: Same-Origin Policy Bypass in Firefox JAR Component
CVE-2026-8971 6.5 - Medium - May 19, 2026

Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Origin Validation Error

Firefox Privilege Escalation in Security Component before 151/140.11
CVE-2026-8970 8.8 - High - May 19, 2026

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Improper Privilege Management

CVE-2026-8969: Mitigation Bypass in DOM Security Component of Firefox
CVE-2026-8969 8.1 - High - May 19, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Protection Mechanism Failure

Firefox Web Codecs DS via invalid pointer fixed in 151/140.11
CVE-2026-8968 7.5 - High - May 19, 2026

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Resource Exhaustion

Info Disclosure via WebGPU in Firefox
CVE-2026-8967 7.5 - High - May 19, 2026

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Information Disclosure

Information disclosure in Mozilla Firefox IP Protection component
CVE-2026-8966 7.5 - High - May 19, 2026

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Information Disclosure

Firefox DOM Info Disclosure (CVE-2026-8965) Fix/Update
CVE-2026-8965 7.5 - High - May 19, 2026

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Information Disclosure

Firefox Popup Blocker Spoofing Vulnerability (CVE-2026-8964)
CVE-2026-8964 7.5 - High - May 19, 2026

Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

User Interface (UI) Misrepresentation of Critical Information

Firefox Web Speech Spoofing Vulnerability
CVE-2026-8963 7.5 - High - May 19, 2026

Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Authentication Bypass by Spoofing

Firefox 151/ESR 140.11 DOM Mitigation Bypass Security Component
CVE-2026-8962 8.1 - High - May 19, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Protection Mechanism Failure

Firefox Form Autofill Spoofing CVE-2026-8961 (fixed in 151/ESR 140.11)
CVE-2026-8961 6.5 - Medium - May 19, 2026

Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Authentication Bypass by Spoofing

Firefox 151 WebExt Spoofing Vulnerability
CVE-2026-8960 7.5 - High - May 19, 2026

Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Authentication Bypass by Spoofing

Firefox 151 Win32 Widget Sandbox Escape - Boundary Condition Flaw
CVE-2026-8959 9.6 - Critical - May 19, 2026

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Buffer Overflow

Firefox 151 Information Disclosure Process Sandbox Escape
CVE-2026-8958 8.6 - High - May 19, 2026

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Exposure of Resource to Wrong Sphere

Privilege Escalation in Firefox Enterprise Policies (before 151)
CVE-2026-8957 8.8 - High - May 19, 2026

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Improper Privilege Management

Integer Overflow in Firefox Networking JAR (150)
CVE-2026-8956 9.8 - Critical - May 19, 2026

Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Integer Overflow or Wraparound

Firefox Workers DOM Privilege Escalation (Pre151)
CVE-2026-8955 8.8 - High - May 19, 2026

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Improper Privilege Management

Integer Overflow in Firefox AV Comp (before 151/ESR 140.11)
CVE-2026-8954 7.5 - High - May 19, 2026

Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Buffer Overflow

Firefox Sandbox Escape via Use-After-Free in Disability Access APIs (before 151)
CVE-2026-8953 9.6 - Critical - May 19, 2026

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Dangling pointer

Firefox PrivEsc via Application Update component CVE-2026-8952
CVE-2026-8952 8.8 - High - May 19, 2026

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Improper Privilege Management

Spoofing Flaw in Firefox for Android Toolbar
CVE-2026-8951 6.5 - Medium - May 19, 2026

Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.

Authentication Bypass by Spoofing

Same-origin policy bypass in Firefox Networking:HTTP component before 151
CVE-2026-8950 9.3 - Critical - May 19, 2026

Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Origin Validation Error

Firefox 151 Integer Overflow in Widget: Win32 Component (pre-151)
CVE-2026-8949 7.5 - High - May 19, 2026

Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Integer Overflow or Wraparound

CVE-2026-8948: Same-origin policy bypass in Firefox DOM networking
CVE-2026-8948 9.1 - Critical - May 19, 2026

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Permissive Cross-domain Policy with Untrusted Domains

Use-After-Free in WebIDL Bindings (Firefox <151)
CVE-2026-8947 7.3 - High - May 19, 2026

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Dangling pointer

Firefox Web Codecs Incorrect Boundary Conditions <151 (ESR 115/140)
CVE-2026-8946 7.5 - High - May 19, 2026

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Buffer Overflow

Firefox Sandbox Escape (Android Focus & Desktop)
CVE-2026-8945 7.5 - High - May 19, 2026

Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

Protection Mechanism Failure

Firefox 150.0.3 Sandbox Escape in Profile Backup (Fixed)
CVE-2026-8401 9.8 - Critical - May 12, 2026

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Protection Mechanism Failure

JavaScript Engine flaw in Firefox 150.0.3 (fixed)
CVE-2026-8391 5.3 - Medium - May 12, 2026

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Improper Input Validation

Firefox WebAssembly Component UAF (pre-150.0.3)
CVE-2026-8390 7.3 - High - May 12, 2026

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

Dangling pointer

Firefox JIT Miscompilation in JS Engine, Fixed in 150.0.3
CVE-2026-8389 7.3 - High - May 12, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

Function Call With Incorrect Argument Type

Firefox 150 JIT Boundary Condition Vulnerability in JS Engine
CVE-2026-8388 6.5 - Medium - May 12, 2026

Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Buffer Overflow

Firefox ESR 140.10.2 WebRTC Vulnerability
CVE-2026-8094 9.8 - Critical - May 07, 2026

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Code Injection

Firefox 150.0.1 Memcor bugs may allow arbitrary code execution
CVE-2026-8093 8.1 - High - May 07, 2026

Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.

Buffer Overflow

Firefox 115.35.1/140.10.1/150.0.1 Memory Safety Bug
CVE-2026-8092 8.1 - High - May 07, 2026

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Out-of-bounds Read

Firefox ESR AV Playback boundary flaw before 140.10.2
CVE-2026-8091 9.8 - Critical - May 07, 2026

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

Improper Check for Unusual or Exceptional Conditions

Use-after-free in Firefox DOM Networking pre-150.0.2
CVE-2026-8090 7.3 - High - May 07, 2026

Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Dangling pointer

Firefox Sandbox Escape in WebRTC Networking before ESR 140.10.1
CVE-2026-7321 9.6 - Critical - April 28, 2026

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

Classic Buffer Overflow

Memory safety bugs in Firefox 150.0.0 (fixed 150.0.1)
CVE-2026-7324 7.3 - High - April 28, 2026

Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.

Buffer Overflow

Memory Safety Bug in Firefox ESR 140.10.0 & Thunderbird 140.10.0
CVE-2026-7323 7.3 - High - April 28, 2026

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

Buffer Overflow

Memory safety bugs in Firefox ESR 115.35.0/140.10.0 & 150.0.0 (fixed 150.0.1)
CVE-2026-7322 7.3 - High - April 28, 2026

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

Buffer Overflow

Firefox Audio/Video Boundary Bug Info Disclosure (fixed in 150.0.1)
CVE-2026-7320 7.5 - High - April 28, 2026

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

Buffer Overflow

Firefox 149 / ESR 140.9 Memory Safety Bugs (Arbitrary Code Exec)
CVE-2026-6786 8.1 - High - April 21, 2026

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Dangling pointer

Mozilla Firefox Memory Safety Bug (ESR 115.34, 115.35, ESR 140.9/140.10, 149)
CVE-2026-6785 8.1 - High - April 21, 2026

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Out-of-bounds Read

Memory Safety Bugs in Firefox 149 & Thunderbird 149
CVE-2026-6784 7.5 - High - April 21, 2026

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Out-of-bounds Read

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mozilla Firefox or by Mozilla? Click the Watch button to subscribe.

Mozilla
Vendor

Mozilla Firefox
Open source web browser

subscribe