[CIVN-2026-0387] Multiple Vulnerabilities in Mozilla Products

By Published On: August 5, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Mozilla Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Mozilla Firefox versions prior to 153

Mozilla Firefox ESR versions prior to 115.38 and Firefox ESR versions prior to 140.13 

Mozilla Thunderbird ESR versions prior to 140.13 and Thunderbird versions prior to 153

Overview


Multiple vulnerabilities have been reported in Mozilla products which could be exploited by a remote attacker to execute arbitrary code, obtain sensitive information, perform spoofing attacks, bypass security restrictions, escalate privileges, escape browser sandbox protections, or cause a Denial of Service (DoS) condition on the targeted system.


Target Audience:

Individuals and organizations using the affected products.


Risk Assessment:

High risk of unauthorized access to sensitive information.


Impact Assessment:

Potential for data theft, sensitive information disclosure and complete compromise of system.


Description


Mozilla Firefox is a free and open-source web browser developed by the Mozilla Foundation, while Firefox ESR (Extended Support Release) is a stable version designed for organizations requiring long-term support with security and maintenance updates. Mozilla Thunderbird is an open-source email client developed by the Mozilla Foundation.


Multiple vulnerabilities exist in the affected Mozilla products due to invalid pointer dereference, incorrect boundary conditions, integer overflow, information disclosure, memory safety flaws, use-after-free, sandbox escape, mitigation bypass, privilege escalation, same-origin policy bypass, and spoofing issues in various components including Audio/Video, JavaScript Engine, DOM, Networking, Graphics, Security, Widget, WebRTC, Enterprise Policies, Profile Backup, Form Autofill, Popup Blocker, Toolbar, Web Speech, WebExtensions, Application Update, and Accessibility APIs. A remote attacker could exploit these vulnerabilities by convincing a user to visit a specially crafted web page or process malicious web content.


Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, disclose sensitive information, perform spoofing attacks, bypass security restrictions, escalate privileges, or cause a Denial of Service (DoS) condition on the targeted system.


Solution


Apply appropriate updates as mentioned in:

https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/



Vendor Information


Mozilla

https://www.mozilla.org/en-US/security/advisories/


References


 

https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/


CVE Name

CVE-2026-15718

CVE-2026-15719

CVE-2026-16349

CVE-2026-16350

CVE-2026-16362

CVE-2026-16351

CVE-2026-16352

CVE-2026-16363

CVE-2026-16353

CVE-2026-16354

CVE-2026-16368

CVE-2026-16369

CVE-2026-16355

CVE-2026-16356

CVE-2026-16357

CVE-2026-16371

CVE-2026-16374

CVE-2026-16375

CVE-2026-16377

CVE-2026-16379

CVE-2026-16358

CVE-2026-16381

CVE-2026-16383

CVE-2026-16387

CVE-2026-16390

CVE-2026-16391

CVE-2026-16359

CVE-2026-16396

CVE-2026-16405

CVE-2026-16412

CVE-2026-16360

CVE-2026-16361

CVE-2026-16364

CVE-2026-16365

CVE-2026-16366

CVE-2026-16367

CVE-2026-16370

CVE-2026-16372

CVE-2026-16373

CVE-2026-16376

CVE-2026-16378

CVE-2026-16380

CVE-2026-16382

CVE-2026-16384

CVE-2026-16385

CVE-2026-16386

CVE-2026-16388

CVE-2026-16389

CVE-2026-16392

CVE-2026-16393

CVE-2026-16394

CVE-2026-16395

CVE-2026-16397

CVE-2026-16398

CVE-2026-16399

CVE-2026-16400

CVE-2026-16401

CVE-2026-16402

CVE-2026-16403

CVE-2026-16404

CVE-2026-16406

CVE-2026-16407

CVE-2026-16408

CVE-2026-16409

CVE-2026-16410

CVE-2026-16411

CVE-2026-14899




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzQ6UACgkQ3jCgcSdc

ys+SyA//QOkOdj5EByrc9TDIgdpDotWG90LtmW0L8DOjq2noU0ZYmygcuOhdGJdV

ARNpznJGTcfirxMuFDt6sTSSxDDXMagEjpE+4Mky13kLX7OiZGuxbAGJROb6INLU

iGDEQaTyg7q3dj9TUd4s4w6yjULjC2AIJD1uEcZAXruJGinR0r6JDIPW3GSXBUAR

uL1aOTkG16sukecwNy3B5dTBYNNTXIz1P9PP54hnrEIeWPY9lRhhqLo1EPRGAAX+

hy81tuDmtTCxQDtBU5eDrekOKBbcfbgbx8+UaXQPtxULLG6rr4LoH7eeUsaTGTTT

jyPi2ieGh9PU1OnpIisfFMWt27BY8+Pv+emCp/IITNEJFLPV9wJ+TN45GC8J0+DL

DY3Cdh+mc/AV6z1mnIuNhvZV1fAWATlK3YWFZWURDg61cbOORBGRjSvSxehPmq4d

ytP5+ZR9SMRNfXlaGzJ9YnjWnSq0RKG6JGW1c084XgUj0WBxo+WHc7Bg5W7yR6v6

TW+qc7hIobNXZfugC8YjMp16uWFGeX8/OmGu6hiK2MTsx28OV0gLQguaToATfWO1

k9L4trNtukMpcy7cqzkZhgBEmrm1TA6J9JapPiFu2w4yFMRMYaJGfEtmIDaGWr6B

Gy01nj6faIBeaRPoYcbUV+jDfI58T//oDfMaZwjjDjPw3XPt4Kk=

=ixBL

—–END PGP SIGNATURE—–

Share this article