[CIVN-2026-0439] Multiple Vulnerabilities in Mozilla Products

By Published On: September 7, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Mozilla Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Mozilla Firefox versions prior to 155

Mozilla Firefox ESR versions prior to 115.40, 140.15, and 153.2

Mozilla Thunderbird versions prior to 140.15, 153.2, and 155

Overview


Multiple vulnerabilities have been reported in Mozilla Products that could allow a remote attacker to exploit the vulnerabilities to cause denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, and spoofing on the affected systems.


Target Audience:

All organizations and individuals using the affected Mozilla Firefox, Firefox ESR, and Thunderbird products.


Risk Assessment:

High risk of unauthorized access, remote code execution, privilege escalation, information disclosure, and security boundary bypass.


Impact Assessment:

Potential for data theft, sensitive information disclosure and compromise of affected systems.


Description


Mozilla Firefox is a free and open-source web browser developed by Mozilla. Firefox ESR (Extended Support Release) is a version of Firefox intended for organizations that require extended support and stability. Mozilla Thunderbird is an open-source email client developed by the Mozilla.


Multiple vulnerabilities have been reported in Mozilla Firefox, Firefox ESR, and Thunderbird due to memory safety issues, useafter-free vulnerabilities, improper security boundary enforcement, race conditions, privilege escalation flaws, information disclosure issues, and other security-related flaws.


Successful exploitation of these vulnerabilities could allow a remote attacker to exploit the vulnerabilities to cause denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, and spoofing on the affected systems.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/


https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/



Vendor Information


Mozilla

https://www.mozilla.org/en-US/security/advisories/


References


Mozilla

https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/

https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/


CVE Name

CVE-2026-16365

CVE-2026-16371

CVE-2026-74952

CVE-2026-75874

CVE-2026-81267

CVE-2026-84117

CVE-2026-84118

CVE-2026-84119

CVE-2026-84120

CVE-2026-84121

CVE-2026-84122

CVE-2026-84123

CVE-2026-84124

CVE-2026-84125

CVE-2026-84126

CVE-2026-84127

CVE-2026-84128

CVE-2026-84129

CVE-2026-84130

CVE-2026-84131

CVE-2026-84132

CVE-2026-84133

CVE-2026-84134

CVE-2026-84135

CVE-2026-84136

CVE-2026-84137

CVE-2026-84138

CVE-2026-84139

CVE-2026-84140

CVE-2026-84141

CVE-2026-84142

CVE-2026-84143

CVE-2026-84144

CVE-2026-84145

CVE-2026-84637

CVE-2026-84639

CVE-2026-84640

CVE-2026-84641

CVE-2026-84642




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe1T0ACgkQ3jCgcSdc

ys/++g//RgwW2IbGNBm37ZTC64tS8jDzePECLG0+XgCB3Rz14PX5tC5bTUt5TZk8

IbzVIZCTGJydJbhEDptn5bxGQ1lBdD1hbD/Jym8d473t7yEWfwXMd7zCOX2j6HY/

ct1bG7i1O+R61OF/qSGt194pSrtuVc2lJs7BWQPGA68UWH8HaerUeYJZyzRK75Vc

v7yA6OZW//8gYEFrkG87URdGVIn2Sfn3LDisZMYKNhosJFBfzAgHPOQGsc6ByCOA

D1QHC5C1f2ZlB3BKKusnUj8SxtadoBtF99yzvlGL4kllnhdGct/nHGjAj4qtUH0L

Lpfsiis3t7gidXZLsep4fBm4PovRc8Js1kHCA3L33V8omcQu5t4VhsEkwkB0AZKu

hdD4LI9AzaqCsuPykURWpIRkjR+oCDPhEY5QmR35rjQRQmnwi55LijUAHqm9nJCm

6TmXpyVUHqDRRZUYuRYxdZvaaUpEfs/85ag+JK2TexBABlOBOwcLyCmlkbjFQGUB

3WRlBJyH+KnxlkM6f3Z30LyxJ/UgK/VkSxuEjVKknsH95mEDv1pqr3uRT7eBHMRX

Wml8UtLDI+qG++o8aRU6FkizylBpOz/1a7uE0xM3I8KlItAZsEgZxOnXGWgqr6N7

9N2CSZC/URQQeLDNmfPyHSST4RAEe5lyCkx19B0DqunqUh+tY9I=

=rMZ2

—–END PGP SIGNATURE—–

Share this article