mozilla has 182 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 85 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 79. The median CVSS is 8.8 (high), with 40 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-416 (37) and CWE-119 (25). Most affected products: Firefox (149), firefox_mobile (27), thunderbird (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 2% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —(1)
- Last 90 days
- 85 prev 33
Weakness classes
Products
- Firefox 149
- firefox_mobile 27
- thunderbird 3
- firefox_focus 2
- Firefox for iOS 1
Worst active — by depth score
CVE-2024-9680Critical· 9.8An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines89CVE-2022-26486Critical· 9.6An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape78CVE-2022-26485High· 8.8Removing an XSLT parameter during processing could have lead to an exploitable use-after-free76CVE-2026-74943Critical· 9.8Use-after-free in the Graphics: ImageLib component66CVE-2026-74936Critical· 9.8Use-after-free in the JavaScript: WebAssembly component66
mozilla vulnerabilities
CVEs affecting mozilla, newest first. Open any entry for full detail, references, and exploit status.
182 CVEsRSS
CVE-2026-92053High· 8.8⚖ disputedPrivilege escalation in the Graphics: CanvasWebGL component
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92059Critical· 9.3⚖ disputedIncorrect boundary conditions in the DOM: Editor component
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92058High· 8.8⚖ disputedUse-after-free in the Graphics component
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92057Critical· 9.1⚖ disputedMitigation bypass in the Enterprise Policies component
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92063Medium· 6.5⚖ disputedDenial-of-service in the Audio/Video component
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92062High· 8.8⚖ disputedPrivilege escalation in the Session Restore component
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92060High· 8.8⚖ disputedUse-after-free in the Internationalization component
Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92066Critical· 9.8⚖ disputedSandbox escape in the Profile Backup component
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92061Critical· 9.8⚖ disputedIncorrect boundary conditions in the Security: Process Sandboxing component
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92070Medium· 4.3Information disclosure in the Networking component
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92069Medium· 5.4⚖ disputedSpoofing issue in the DOM: Navigation component
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92067High· 8.8⚖ disputedUse-after-free in the Widget: Gtk component
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92071Critical· 9.6⚖ disputedSandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92068Medium· 5.4⚖ disputedSite isolation issue in the Reader Mode component
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92064High· 8.8⚖ disputedSandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92073High· 8.8⚖ disputedPrivilege escalation in the Enterprise Policies component
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92072High· 8.0⚖ disputedIncorrect boundary conditions in the Safe Browsing component
Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92065High· 8.8⚖ disputedSandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-86853Medium· 4.3A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches
A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Fi…
CVE-2026-74983High· 8.1Mitigation bypass in the Data Loss Prevention component
Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74961Critical· 9.1Side-channel in the Web Audio component
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-74944Critical· 9.8⚖ disputedUse-after-free in the DOM: Core & HTML component
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74943Critical· 9.8PoC⚖ disputedUse-after-free in the Graphics: ImageLib component
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74940Critical· 9.8⚖ disputedUse-after-free in the Graphics: Text component
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74936Critical· 9.8PoC⚖ disputedUse-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-12329Medium· 5.3Memory safety bug fixed in Thunderbird ESR 140.12
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
CVE-2026-12328High· 8.1Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151
Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c…
CVE-2026-12299Medium· 5.4JIT miscompilation in the DOM: Core & HTML component
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
CVE-2026-12298Medium· 5.4Memory safety bug fixed in Firefox 152
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
CVE-2026-12297Critical· 9.6Sandbox escape due to incorrect boundary conditions in the Networking component
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.