PatchSiren cyber security CVE debrief
CVE-2026-8953 Mozilla CVE debrief
CVE-2026-8953 is a critical Mozilla vulnerability involving a use-after-free in the Disability Access APIs component. Mozilla states it was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. Because the flaw can lead to sandbox escape and carries a CVSS 3.1 score of 9.6, it should be treated as an urgent patching priority for browsers and mail clients still on affected releases.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-19
Who should care
Security teams, endpoint administrators, and individual users running Firefox, Firefox ESR, or Thunderbird on versions earlier than the fixed releases. Organizations that rely on managed browser or mail-client update cycles should prioritize this issue immediately.
Technical summary
The NVD record describes CVE-2026-8953 as a use-after-free (CWE-416) in Mozilla’s Disability Access APIs component. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, indicating network-based exposure with low attack complexity, no privileges required, and user interaction required. The security impact is severe because the flaw can be used for sandbox escape, expanding impact beyond the initial browser or application boundary.
Defensive priority
Immediate
Recommended defensive actions
- Update Firefox to 151 or later.
- Update Firefox ESR to 115.36 or 140.11 or later, depending on the deployed ESR branch.
- Update Thunderbird to 151 or later, or 140.11 or later for the 140 ESR branch.
- Verify fleet inventory for all Mozilla browser and mail-client installations, including unmanaged endpoints.
- Treat the issue as high priority in standard patch queues because the CVSS score is 9.6 and the vulnerability enables sandbox escape.
- Review Mozilla’s vendor advisories and the linked Bugzilla issue for any deployment-specific guidance.
Evidence notes
All facts in this debrief come from the supplied CVE/NVD metadata and the provided Mozilla reference links. The record identifies the flaw as a sandbox escape due to a use-after-free in the Disability Access APIs component, with CWE-416 listed in NVD. The affected and fixed versions are taken from the NVD CPE criteria and the CVE description: Firefox fixed in 151, Firefox ESR fixed in 115.36 and 140.11, and Thunderbird fixed in 151 and 140.11. The CVE was published on 2026-05-19.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8953 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8953
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8953 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8953
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-46/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-47/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-48/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-50/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-51/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.