[CIVN-2026-0418] Multiple Vulnerabilities in Mozilla Products

By Published On: August 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Mozilla Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Mozilla Firefox versions prior to 154

Mozilla Firefox ESR versions prior to 115.39, 140.14 and 153.1

Mozilla Thunderbird versions prior to 140.14, 153.1 and 154

Overview


Multiple vulnerabilities have been reported in Mozilla Firefox, Firefox ESR, and Thunderbird that could allow an attacker to bypass security protections, disclose sensitive information, escalate privileges, or cause denial-of-service conditions on affected systems.


Target Audience:

All organizations and individuals using the affected Mozilla Firefox, Firefox ESR, and Thunderbird products.


Risk Assessment:

High risk of unauthorized access, privilege escalation, information disclosure, security boundary bypass, and compromise of affected systems.


Impact Assessment:

Potential for data theft, sensitive information disclosure and compromise of affected systems.


Description


Mozilla Firefox is a free and open-source web browser developed by Mozilla. Firefox ESR (Extended Support Release) is a version of Firefox intended for organizations that require extended support and stability. Mozilla Thunderbird is an open-source email client developed by the Mozilla.


Multiple vulnerabilities have been reported in Mozilla Firefox, Firefox ESR, and Thunderbird due to memory safety issues, use-after-free vulnerabilities, improper security boundary enforcement, race conditions, privilege escalation flaws, information disclosure issues, and other security-related flaws.


Successful exploitation of these vulnerabilities could allow an attacker to bypass security protections, disclose sensitive information, escalate privileges, or cause denial-of-service conditions on affected systems.


Solution


Apply appropriate security updates as recommended by the vendor.

https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-75/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/



Vendor Information


Mozilla

https://www.mozilla.org/en-US/security/advisories/


References


 

https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-75/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/


CVE Name

CVE-2026-74934

CVE-2026-74935

CVE-2026-74936

CVE-2026-74937

CVE-2026-74938

CVE-2026-74939

CVE-2026-74940

CVE-2026-74941

CVE-2026-74942

CVE-2026-74943

CVE-2026-74944

CVE-2026-74945

CVE-2026-74946

CVE-2026-74947

CVE-2026-74948

CVE-2026-74949

CVE-2026-74950

CVE-2026-74951

CVE-2026-74952

CVE-2026-74953

CVE-2026-74954

CVE-2026-74955

CVE-2026-74956

CVE-2026-74957

CVE-2026-74958

CVE-2026-74959

CVE-2026-74960

CVE-2026-74961

CVE-2026-74962

CVE-2026-74963

CVE-2026-74964

CVE-2026-74965

CVE-2026-74966

CVE-2026-74967

CVE-2026-74968

CVE-2026-74969

CVE-2026-74970

CVE-2026-74971

CVE-2026-74972

CVE-2026-74973

CVE-2026-74974

CVE-2026-74975

CVE-2026-74976

CVE-2026-74977

CVE-2026-74978

CVE-2026-74979

CVE-2026-74980

CVE-2026-74981

CVE-2026-74982

CVE-2026-74983

CVE-2026-74984

CVE-2026-74985

CVE-2026-74986

CVE-2026-74987

CVE-2026-74988

CVE-2026-74989

CVE-2026-74990

CVE-2026-75874




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqNpAwACgkQ3jCgcSdc

ys+OnQ//ZyGyU3yQ7qkFwpceNekv82AM/M1O9zfhBu9jaNMRJe9/kLOvw6Z+qt2V

El8Z6QKmWKFApL+v46GVQj46iY+6YJMaJA6nw0M32LR3dV42xZKZt+2ZZNWgH4/O

bo9DLpq8JTbbgAn0jxdTqopNpgyEvEOZBB21FQQHQwPZflotpcdr2qMyKtFlez2X

k+cxAZGFTDTs4t4MTZG10CJiq7ZAq7OmDptvaxAcpbQ1eCtWrZVj+CkcpvwXovRL

WPoY4Zsiqh3OLha3g/suMlv8VbGpPKhqYBcOwVQqmOJkwBV+mQr5bnyAfVSZLAzt

lgGBKVnHvUCK1I952jNwQafC4iroQP2/ELWkkXSx4nO0+XVDfy/lecEfrEB9ow6O

yYSWS515djLKJJvcOCxxUZIpWV//7rSqIA33XAM0a216rbnlarNEH/gEdYDVODlK

vQTIZzDo9UNVzZMWBRLpTZyPjQ/QZUbJHmPM+0rUtBnU32n+XdxOC3KxyrUj7j/z

vkXrldA5oUGsZ7WHC/gQ8RuAKqb0GRv/akRfL8PT0cdukC3VQKFhhIB7XolNHg5f

qZgjAVpSjBe5u2fkCyPyzjR0I1RCbxUgRYTHFtbBoNYtfz2KNR7vChMfQFid3K/E

xkQ+1kOoDytRbuS0Bno6NAeB0ko9XkQtmD8bkAhw4DTT/CR7Pno=

=aQzt

—–END PGP SIGNATURE—–

Share this article