Mozilla Vulnerabilities
Comprehensive security vulnerability database for Mozilla products
28
28
32
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-2785 | 9.8 | This vulnerability allows an attacker to potentially execute malicious code on a user's system through Firefox or Thunderbird, which could lead to full control over the affected device. It specifically affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2784 | 9.8 | This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of sensitive information. It affects users running versions earlier than 148 for Firefox and 148 for Thunderbird, meaning those who haven't updated their software are at risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2782 | 9.8 | This critical vulnerability allows an attacker to gain higher access privileges within Firefox and Thunderbird, potentially letting them execute harmful actions on a user's system. It affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2781 | 9.8 | This critical vulnerability allows an attacker to potentially execute malicious code on a user's system through affected versions of Firefox and Thunderbird. It requires the user to visit a specially crafted website or open a malicious email, making it essential for users to update their software to the latest versions to stay protected. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2780 | 9.8 | This critical vulnerability allows an attacker to gain higher privileges within Firefox or Thunderbird, potentially letting them execute harmful actions on the user's system. It affects versions prior to 148 for Firefox and Thunderbird, and requires the attacker to exploit the Netmonitor component to take advantage of this flaw. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2779 | 9.8 | This vulnerability allows an attacker to potentially execute malicious code on a user's system through specially crafted JAR files when using affected versions of Firefox or Thunderbird. To exploit this, the attacker needs to trick the user into opening a compromised JAR file, which can lead to severe security breaches. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2778 | 10.0 | This critical vulnerability allows an attacker to break out of the browser's security sandbox, potentially gaining access to sensitive data or executing malicious code on the user's system. It affects specific versions of Firefox and Thunderbird, so users running outdated software are at higher risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2777 | 9.8 | This vulnerability allows an attacker to gain higher access privileges within the messaging system of Firefox and Thunderbird, potentially letting them execute harmful actions on the user's system. It affects specific versions of these applications, so users running outdated software are at greater risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2776 | 10.0 | This critical vulnerability allows an attacker to break out of the security sandbox in Firefox and Thunderbird, potentially gaining access to sensitive information or executing malicious code on the user's system. It affects versions of Firefox and Thunderbird prior to 148 and certain ESR versions, meaning users need to update their software to stay protected. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2775 | 9.8 | This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of web content. It affects specific versions of these browsers, so users need to update to the latest versions to protect themselves. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2774 | 9.8 | This critical vulnerability allows an attacker to potentially execute harmful code on a user's system by exploiting an integer overflow in the audio/video component of Firefox and Thunderbird. It affects specific versions of these applications, so users running outdated versions are at risk if they visit a malicious website or open a compromised file. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2773 | 9.8 | This vulnerability allows an attacker to potentially execute harmful code on a user's system through the Web Audio feature in affected versions of Firefox and Thunderbird. It requires the user to visit a malicious website or open a compromised file that exploits this flaw, putting their device at risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2772 | 9.8 | This vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in how Firefox and Thunderbird handle audio and video playback. It affects specific older versions of these applications, meaning users need to update to the latest versions to protect themselves. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2771 | 9.8 | This critical vulnerability allows an attacker to execute arbitrary code on a user's system through malicious web content in Firefox and Thunderbird. It affects specific versions of these applications, so users need to ensure they are running the latest updates to stay protected. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2770 | 9.8 | This critical vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in how Firefox and Thunderbird handle certain web components. It affects versions prior to 148 and requires the user to visit a specially crafted website or open a malicious email to trigger the attack. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2768 | 10.0 | This vulnerability allows an attacker to break out of the security sandbox that isolates web applications, potentially giving them access to sensitive data stored in the browser. It affects specific versions of Firefox and Thunderbird, meaning users need to update their software to protect against this risk. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2767 | 9.8 | This vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in the WebAssembly component of Firefox and Thunderbird. It affects versions prior to 148 and 140.8, meaning users with outdated software are at risk if they visit a compromised website or open a malicious email. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2766 | 9.8 | This critical vulnerability allows an attacker to execute malicious code on a user's system by exploiting a flaw in the JavaScript engine of Firefox and Thunderbird. It affects versions prior to 148 and 140.8 for both browsers, meaning users need to update to the latest versions to protect themselves. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2765 | 9.8 | This critical vulnerability allows an attacker to execute malicious code on a user's system through a flaw in the JavaScript engine of Firefox and Thunderbird, potentially leading to unauthorized access or control. It affects specific versions of these applications, so users need to ensure they are updated to the latest versions to protect themselves. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
| CVE-2026-2764 | 9.8 | This critical vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting a flaw in how Firefox and Thunderbird handle JavaScript. It affects specific versions of these applications, so users need to ensure they are running the latest updates to protect against potential attacks. | mozillafirefox | Exploit Available | about 1 month agoFeb 24, 2026 |
About Mozilla Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Mozilla products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.