Mozilla Vulnerabilities

Comprehensive security vulnerability database for Mozilla products

Last updated: Feb 24, 2026
Total CVEs

28

Critical

28

With Exploits

32

Last 30 Days

0

Severity Distribution

Critical28
100%
High3
11%
Medium1
4%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-27859.8

This vulnerability allows an attacker to potentially execute malicious code on a user's system through Firefox or Thunderbird, which could lead to full control over the affected device. It specifically affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27849.8

This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of sensitive information. It affects users running versions earlier than 148 for Firefox and 148 for Thunderbird, meaning those who haven't updated their software are at risk.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27829.8

This critical vulnerability allows an attacker to gain higher access privileges within Firefox and Thunderbird, potentially letting them execute harmful actions on a user's system. It affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27819.8

This critical vulnerability allows an attacker to potentially execute malicious code on a user's system through affected versions of Firefox and Thunderbird. It requires the user to visit a specially crafted website or open a malicious email, making it essential for users to update their software to the latest versions to stay protected.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27809.8

This critical vulnerability allows an attacker to gain higher privileges within Firefox or Thunderbird, potentially letting them execute harmful actions on the user's system. It affects versions prior to 148 for Firefox and Thunderbird, and requires the attacker to exploit the Netmonitor component to take advantage of this flaw.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27799.8

This vulnerability allows an attacker to potentially execute malicious code on a user's system through specially crafted JAR files when using affected versions of Firefox or Thunderbird. To exploit this, the attacker needs to trick the user into opening a compromised JAR file, which can lead to severe security breaches.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-277810.0

This critical vulnerability allows an attacker to break out of the browser's security sandbox, potentially gaining access to sensitive data or executing malicious code on the user's system. It affects specific versions of Firefox and Thunderbird, so users running outdated software are at higher risk.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27779.8

This vulnerability allows an attacker to gain higher access privileges within the messaging system of Firefox and Thunderbird, potentially letting them execute harmful actions on the user's system. It affects specific versions of these applications, so users running outdated software are at greater risk.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-277610.0

This critical vulnerability allows an attacker to break out of the security sandbox in Firefox and Thunderbird, potentially gaining access to sensitive information or executing malicious code on the user's system. It affects versions of Firefox and Thunderbird prior to 148 and certain ESR versions, meaning users need to update their software to stay protected.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27759.8

This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of web content. It affects specific versions of these browsers, so users need to update to the latest versions to protect themselves.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27749.8

This critical vulnerability allows an attacker to potentially execute harmful code on a user's system by exploiting an integer overflow in the audio/video component of Firefox and Thunderbird. It affects specific versions of these applications, so users running outdated versions are at risk if they visit a malicious website or open a compromised file.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27739.8

This vulnerability allows an attacker to potentially execute harmful code on a user's system through the Web Audio feature in affected versions of Firefox and Thunderbird. It requires the user to visit a malicious website or open a compromised file that exploits this flaw, putting their device at risk.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27729.8

This vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in how Firefox and Thunderbird handle audio and video playback. It affects specific older versions of these applications, meaning users need to update to the latest versions to protect themselves.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27719.8

This critical vulnerability allows an attacker to execute arbitrary code on a user's system through malicious web content in Firefox and Thunderbird. It affects specific versions of these applications, so users need to ensure they are running the latest updates to stay protected.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27709.8

This critical vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in how Firefox and Thunderbird handle certain web components. It affects versions prior to 148 and requires the user to visit a specially crafted website or open a malicious email to trigger the attack.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-276810.0

This vulnerability allows an attacker to break out of the security sandbox that isolates web applications, potentially giving them access to sensitive data stored in the browser. It affects specific versions of Firefox and Thunderbird, meaning users need to update their software to protect against this risk.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27679.8

This vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in the WebAssembly component of Firefox and Thunderbird. It affects versions prior to 148 and 140.8, meaning users with outdated software are at risk if they visit a compromised website or open a malicious email.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27669.8

This critical vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in the JavaScript engine of Firefox and Thunderbird. It affects versions prior to 148 and 140.8 for both browsers, meaning users need to update to the latest versions to protect themselves.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27659.8

This critical vulnerability allows an attacker to execute malicious code on a user's system through a flaw in the JavaScript engine of Firefox and Thunderbird, potentially leading to unauthorized access or control. It affects specific versions of these applications, so users need to ensure they are updated to the latest versions to protect themselves.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27649.8

This critical vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting a flaw in how Firefox and Thunderbird handle JavaScript. It affects specific versions of these applications, so users need to ensure they are running the latest updates to protect against potential attacks.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
Showing 1 to 20 of 28 results

About Mozilla Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Mozilla products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.