Mozilla Vulnerabilities
Comprehensive security vulnerability database for Mozilla products
32
28
32
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-2765 | 9.8 | This critical vulnerability allows an attacker to execute malicious code on a user's system through a flaw in the JavaScript engine of Firefox and Thunderbird, potentially leading to unauthorized access or control. It affects specific versions of these applications, so users need to ensure they are updated to the latest versions to protect themselves. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2764 | 9.8 | This critical vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting a flaw in how Firefox and Thunderbird handle JavaScript. It affects specific versions of these applications, so users need to ensure they are running the latest updates to protect against potential attacks. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2763 | 9.8 | This vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in the JavaScript engine of Firefox and Thunderbird. It affects versions prior to 148 and requires the user to visit a specially crafted website or open a malicious email to trigger the attack. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2762 | 9.8 | This critical vulnerability allows an attacker to execute arbitrary code on affected versions of Firefox and Thunderbird, potentially taking control of a user's system. It occurs due to an integer overflow in the JavaScript library, and users need to be running versions earlier than 148 for Firefox or 148 for Thunderbird to be at risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2761 | 10.0 | This critical vulnerability allows an attacker to break out of the security protections in Firefox and Thunderbird, potentially gaining access to sensitive information on the user's system. It affects specific versions of these applications, so users running outdated software are at higher risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2760 | 10.0 | This critical vulnerability allows an attacker to break out of a secure area in Firefox and Thunderbird, potentially gaining access to sensitive system resources. It affects versions prior to 148 for Firefox and 148 for Thunderbird, meaning users need to update their software to stay protected. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2759 | 9.8 | This vulnerability allows an attacker to potentially execute malicious code on a user's system by exploiting flaws in how images are processed in Firefox and Thunderbird. It affects specific versions of these applications, so users running outdated software are at higher risk if they open a compromised image. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2758 | 9.8 | This vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in how Firefox and Thunderbird handle memory, specifically when cleaning up unused data. It affects versions of these applications prior to 148 and certain extended support releases, meaning users need to update to the latest versions to protect themselves. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2757 | 9.8 | This vulnerability allows an attacker to potentially execute harmful code on a user's device through malicious audio or video streams in Firefox and Thunderbird. It affects versions prior to 148 and requires the user to interact with the compromised media, making it critical for users to update their software immediately. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2634 | 9.8 | An attacker can trick users into thinking they are on a legitimate website by displaying fake content under a spoofed domain in Firefox for iOS versions before 147.4. This vulnerability occurs when malicious scripts cause a mismatch between the address bar and the actual web content, potentially leading users to enter sensitive information on a fraudulent site. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2447 | 8.8 | This vulnerability allows an attacker to potentially execute malicious code on a user's system by exploiting a flaw in how Firefox and Thunderbird handle video data. It affects specific versions of these applications, so users need to ensure they are running the latest updates to stay protected. | mozillafirefox | Exploit Available | about 2 months agoFeb 16, 2026 |
| CVE-2026-2032 | 4.3 | An attacker can trick users into seeing fake content that looks legitimate by interrupting the loading of new tabs in Firefox for iOS versions before 147.2.1. This requires the attacker to run malicious scripts during the loading process, which can mislead users into believing they are on a trusted website. | mozillafirefox | Exploit Available | about 2 months agoFeb 16, 2026 |
About Mozilla Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Mozilla products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.