
[CIVN-2026-0439] Multiple Vulnerabilities in Mozilla Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Mozilla Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Mozilla Firefox versions prior to 155
Mozilla Firefox ESR versions prior to 115.40, 140.15, and 153.2
Mozilla Thunderbird versions prior to 140.15, 153.2, and 155
Overview
Multiple vulnerabilities have been reported in Mozilla Products that could allow a remote attacker to exploit the vulnerabilities to cause denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, and spoofing on the affected systems.
Target Audience:
All organizations and individuals using the affected Mozilla Firefox, Firefox ESR, and Thunderbird products.
Risk Assessment:
High risk of unauthorized access, remote code execution, privilege escalation, information disclosure, and security boundary bypass.
Impact Assessment:
Potential for data theft, sensitive information disclosure and compromise of affected systems.
Description
Mozilla Firefox is a free and open-source web browser developed by Mozilla. Firefox ESR (Extended Support Release) is a version of Firefox intended for organizations that require extended support and stability. Mozilla Thunderbird is an open-source email client developed by the Mozilla.
Multiple vulnerabilities have been reported in Mozilla Firefox, Firefox ESR, and Thunderbird due to memory safety issues, useafter-free vulnerabilities, improper security boundary enforcement, race conditions, privilege escalation flaws, information disclosure issues, and other security-related flaws.
Successful exploitation of these vulnerabilities could allow a remote attacker to exploit the vulnerabilities to cause denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, and spoofing on the affected systems.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/
CVE Name
CVE-2026-16365
CVE-2026-16371
CVE-2026-74952
CVE-2026-75874
CVE-2026-81267
CVE-2026-84117
CVE-2026-84118
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84123
CVE-2026-84124
CVE-2026-84125
CVE-2026-84126
CVE-2026-84127
CVE-2026-84128
CVE-2026-84129
CVE-2026-84130
CVE-2026-84131
CVE-2026-84132
CVE-2026-84133
CVE-2026-84134
CVE-2026-84135
CVE-2026-84136
CVE-2026-84137
CVE-2026-84138
CVE-2026-84139
CVE-2026-84140
CVE-2026-84141
CVE-2026-84142
CVE-2026-84143
CVE-2026-84144
CVE-2026-84145
CVE-2026-84637
CVE-2026-84639
CVE-2026-84640
CVE-2026-84641
CVE-2026-84642
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe1T0ACgkQ3jCgcSdc
ys/++g//RgwW2IbGNBm37ZTC64tS8jDzePECLG0+XgCB3Rz14PX5tC5bTUt5TZk8
IbzVIZCTGJydJbhEDptn5bxGQ1lBdD1hbD/Jym8d473t7yEWfwXMd7zCOX2j6HY/
ct1bG7i1O+R61OF/qSGt194pSrtuVc2lJs7BWQPGA68UWH8HaerUeYJZyzRK75Vc
v7yA6OZW//8gYEFrkG87URdGVIn2Sfn3LDisZMYKNhosJFBfzAgHPOQGsc6ByCOA
D1QHC5C1f2ZlB3BKKusnUj8SxtadoBtF99yzvlGL4kllnhdGct/nHGjAj4qtUH0L
Lpfsiis3t7gidXZLsep4fBm4PovRc8Js1kHCA3L33V8omcQu5t4VhsEkwkB0AZKu
hdD4LI9AzaqCsuPykURWpIRkjR+oCDPhEY5QmR35rjQRQmnwi55LijUAHqm9nJCm
6TmXpyVUHqDRRZUYuRYxdZvaaUpEfs/85ag+JK2TexBABlOBOwcLyCmlkbjFQGUB
3WRlBJyH+KnxlkM6f3Z30LyxJ/UgK/VkSxuEjVKknsH95mEDv1pqr3uRT7eBHMRX
Wml8UtLDI+qG++o8aRU6FkizylBpOz/1a7uE0xM3I8KlItAZsEgZxOnXGWgqr6N7
9N2CSZC/URQQeLDNmfPyHSST4RAEe5lyCkx19B0DqunqUh+tY9I=
=rMZ2
—–END PGP SIGNATURE—–


