FireFox Extended Support Release (ESR) Mozilla FireFox Extended Support Release (ESR)

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mozilla FireFox Extended Support Release (ESR).

Recent Mozilla FireFox Extended Support Release (ESR) Security Advisories

Advisory Title Published
mfsa2026-22 Security Vulnerabilities fixed in Firefox ESR 140.9 mfsa2026-22 March 24, 2026
mfsa2026-21 Security Vulnerabilities fixed in Firefox ESR 115.34 mfsa2026-21 March 24, 2026
mfsa2026-15 Security Vulnerabilities fixed in Firefox ESR 140.8 mfsa2026-15 February 24, 2026
mfsa2026-14 Security Vulnerabilities fixed in Firefox ESR 115.33 mfsa2026-14 February 24, 2026
mfsa2026-02 Security Vulnerabilities fixed in Firefox ESR 115.32 mfsa2026-02 January 13, 2026
mfsa2026-03 Security Vulnerabilities fixed in Firefox ESR 140.7 mfsa2026-03 January 13, 2026
mfsa2025-93 Security Vulnerabilities fixed in Firefox ESR 115.31 mfsa2025-93 December 9, 2025
mfsa2025-94 Security Vulnerabilities fixed in Firefox ESR 140.6 mfsa2025-94 December 9, 2025
mfsa2025-88 Security Vulnerabilities fixed in Firefox ESR 140.5 mfsa2025-88 November 11, 2025
mfsa2025-89 Security Vulnerabilities fixed in Firefox ESR 115.30 mfsa2025-89 November 11, 2025

By the Year

In 2026 there have been 87 vulnerabilities in Mozilla FireFox Extended Support Release (ESR) with an average score of 8.8 out of ten. Last year, in 2025 FireFox Extended Support Release (ESR) had 104 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in FireFox Extended Support Release (ESR) in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.16.




Year Vulnerabilities Average Score
2026 87 8.81
2025 104 7.65
2024 62 7.32
2023 109 7.56
2022 103 7.65
2021 59 7.48
2020 82 7.63
2019 63 7.94
2018 166 8.68

It may take a day or so for new FireFox Extended Support Release (ESR) vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla FireFox Extended Support Release (ESR) Security Vulnerabilities

Memory Safety Bug in Firefox (ESR 115.33/140.8 & 148) prior to v149
CVE-2026-4721 9.8 - Critical - March 24, 2026

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Classic Buffer Overflow

Mozilla Firefox <149 & ESR <140.9 Memory Corruption (Thunderbird)
CVE-2026-4720 9.8 - Critical - March 24, 2026

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Classic Buffer Overflow

Firefox Graphics:Text Boundary Condition Flaw (pre-149 / ESR<140.9)
CVE-2026-4719 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics: Text component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Buffer Overflow

Undefined Behavior in WebRTC Signaling of Firefox <149
CVE-2026-4718 8.1 - High - March 24, 2026

Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

Privilege Escalation in Netmonitor of Firefox <149/ESR 140.9
CVE-2026-4717 9.8 - Critical - March 24, 2026

Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Firefox <149/ESR <140.9: JS Engine uninitialized memory
CVE-2026-4716 9.1 - Critical - March 24, 2026

Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Use of Uninitialized Resource

Uninitialized Memory in Firefox Canvas2D component <149/ESR<140.9
CVE-2026-4715 9.1 - Critical - March 24, 2026

Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Use of Uninitialized Resource

Firefox Audio/Video Boundary Condition Flaw (v <149, ESR <140.9)
CVE-2026-4714 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

FF <149 Graphics Boundary Condition Flaw
CVE-2026-4713 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox <149 Info Disclosure via Widget Cocoa Comp (CVE-2026-4712)
CVE-2026-4712 7.5 - High - March 24, 2026

Information disclosure in the Widget: Cocoa component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Information Disclosure

Firefox <149 Use-after-free in Cocoa Widget Component
CVE-2026-4711 9.8 - Critical - March 24, 2026

Use-after-free in the Widget: Cocoa component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Dangling pointer

Firefox AV Boundary Condition Flaw v<149/ESR<140.9
CVE-2026-4710 9.8 - Critical - March 24, 2026

Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Buffer Overflow

Mozilla Firefox <149 Audio/Video: GMP Boundary Condition Vulnerability
CVE-2026-4709 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox Graphics Boundary Flaw (149, ESR<140.9)
CVE-2026-4708 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox <149 Canvas2D Boundary Condition Flaw (CVE20264707)
CVE-2026-4707 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox <149 & ESR <115.34,140.9 Canvas2D Boundary Condition Vulnerability
CVE-2026-4706 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

CVE-2026-4705: WebRTC Signaling UB Firefox <149/ESR <140.9
CVE-2026-4705 9.8 - Critical - March 24, 2026

Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

Firefox <149 Denial-of-Service via WebRTC Signaling
CVE-2026-4704 7.5 - High - March 24, 2026

Denial-of-service in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Resource Exhaustion

Mozilla Firefox <149 JIT Miscompilation in JS Engine (CVE-2026-4702)
CVE-2026-4702 9.8 - Critical - March 24, 2026

JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Object Type Confusion

Use-after-free in Firefox JS Engine before 149 & ESR <140.9
CVE-2026-4701 9.8 - Critical - March 24, 2026

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Dangling pointer

Firefox <149 Mitigation Bypass in Networking:HTTP Component
CVE-2026-4700 9.8 - Critical - March 24, 2026

Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Authentication Bypass Using an Alternate Path or Channel

Firefox <149 Boundary Error in Layout Text & Fonts
CVE-2026-4699 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox <149 JIT-Miscompilation SpiderMonkey
CVE-2026-4698 9.8 - Critical - March 24, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Object Type Confusion

UA-Free in Firefox Layout:Text & Fonts v<149 (ESR<115.34)
CVE-2026-4696 9.8 - Critical - March 24, 2026

Use-after-free in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Dangling pointer

Firefox <149 Audio/Video Web Codecs boundary flaw
CVE-2026-4697 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox <149: Incorrect Boundary Conditions in Audio/Video Web Codecs
CVE-2026-4695 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Integer Overflow Firefox Graphics <=149 (ESR<115.34)
CVE-2026-4694 7.5 - High - March 24, 2026

Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox <149/ESR<140.9 AV Playback Boundary Check Failure
CVE-2026-4693 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

CVE-2026-4692: Sandbox Escape via Responsive Design Mode in Firefox <149
CVE-2026-4692 9.6 - Critical - March 24, 2026

Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Firefox CSS Parsing Use-After-Free (before 149, ESR <115.34/140.9)
CVE-2026-4691 9.8 - Critical - March 24, 2026

Use-after-free in the CSS Parsing and Computation component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Dangling pointer

Firefox <149 XPCOM Sandbox Escape (CVE-2026-4690)
CVE-2026-4690 9.6 - Critical - March 24, 2026

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Integer Overflow or Wraparound

Firefox <149 Sandbox Escape: XPCOM Integer Overflow
CVE-2026-4689 10 - Critical - March 24, 2026

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Classic Buffer Overflow

Firefox <149/ESR<140.9: Disability Access API UAF Sandbox Escape
CVE-2026-4688 9.6 - Critical - March 24, 2026

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Dangling pointer

Firefox <149 Sandbox Escape via Telemetry Boundary Conditions
CVE-2026-4687 9.6 - Critical - March 24, 2026

Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Classic Buffer Overflow

Firefox Canvas2D Incorrect Boundary Conditions ( Firefox 149 / ESR 140.9)
CVE-2026-4686 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

Firefox Canvas2D boundary flaw before v149/ESR115.34/ESR140.9
CVE-2026-4685 7.5 - High - March 24, 2026

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Improper Check for Unusual or Exceptional Conditions

WebRender Use-After-Free Race in Firefox <149 (ESR <115.34/140.9)
CVE-2026-4684 7.5 - High - March 24, 2026

Race condition, use-after-free in the Graphics: WebRender component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Dangling pointer

Memory Safety Bug in Firefox ESR <115.33/140.8; <148 for FF/Thunderbird
CVE-2026-2793 9.8 - Critical - February 24, 2026

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Memory Corruption

Memory Safety Bugs in Firefox 147 & ESR 140.7, Thunderbird 147 & ESR 140.7
CVE-2026-2792 9.8 - Critical - February 24, 2026

Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Memory Corruption

Firefox <148 / ESR<140.8: Networking Cache Mitigation Bypass
CVE-2026-2791 9.8 - Critical - February 24, 2026

Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Authentication Bypass Using an Alternate Path or Channel

Firefox Same-origin policy bypass in JAR component before 148/ESR 140.8
CVE-2026-2790 - February 24, 2026

Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 148 and Firefox ESR < 140.8.

Use-after-free in Graphics ImageLib of Firefox <148 (ESR <115.33/140.8)
CVE-2026-2789 8.8 - High - February 24, 2026

Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Dangling pointer

Firefox <148 Boundary Condition Flaw in Audio/Video GMP
CVE-2026-2788 9.8 - Critical - February 24, 2026

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Buffer Overflow

UAF in Firefox DOM Window/Location before v148
CVE-2026-2787 8.8 - High - February 24, 2026

Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Dangling pointer

Use-after-free in Firefox JS Engine (before 148)
CVE-2026-2786 8.8 - High - February 24, 2026

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Firefox <148/ESR<140.8: Invalid Pointer in JS Engine
CVE-2026-2785 8.8 - High - February 24, 2026

Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Access of Uninitialized Pointer

Firefox <148 & ESR<140.8: DOM Mitigation Bypass in Security Component
CVE-2026-2784 9.8 - Critical - February 24, 2026

Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Authentication Bypass Using an Alternate Path or Channel

Firefox <=148 Info Disclosure via JIT Miscomp
CVE-2026-2783 - February 24, 2026

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148 and Firefox ESR < 140.8.

Firefox <148 ESR <140.8 Integer Overflow in NSS Libraries
CVE-2026-2781 8.8 - High - February 24, 2026

Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Integer Overflow or Wraparound

Firefox Netmonitor Privilege Escalation (v<148/ESR<140.8)
CVE-2026-2782 8.8 - High - February 24, 2026

Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Improper Privilege Management

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mozilla FireFox Extended Support Release (ESR) or by Mozilla? Click the Watch button to subscribe.

Mozilla
Vendor

subscribe