PatchSiren cyber security CVE debrief
CVE-2026-8955 Mozilla CVE debrief
CVE-2026-8955 is a Mozilla privilege-escalation issue in the DOM Workers component. NVD rates it 8.8 HIGH with a network-reachable attack path that requires user interaction. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird ESR 140.11. The supplied corpus does not include the full advisory text, so the most reliable details here come from the CVE record, NVD metadata, and Mozilla reference links.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-20
Who should care
Mozilla Firefox and Thunderbird users and administrators, especially teams managing enterprise desktop fleets, ESR deployments, and environments where browser or mail-client updates are staged centrally. Security teams should prioritize systems that run affected Firefox or Thunderbird branches before the fixed releases.
Technical summary
The supplied record describes a privilege-escalation flaw in Mozilla's DOM Workers component. NVD maps the issue to CWE-269 and assigns CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating remote exploitation with user interaction required and high potential impact if triggered. Affected versions are those before Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird ESR 140.11. No deeper root-cause details are provided in the corpus.
Defensive priority
High. Treat as a priority patch because the issue is remotely reachable, requires only user interaction, and is already fixed in released Mozilla builds.
Recommended defensive actions
- Update Firefox to 151 or later, or Firefox ESR to 140.11 or later.
- Update Thunderbird to 151 or later, or Thunderbird ESR to 140.11 or later.
- Verify which release channel each managed endpoint is on before staging updates.
- Prioritize internet-facing and high-use user endpoints where interaction with web content or mail content is routine.
- Use the Mozilla advisory and Bugzilla references to confirm fleet applicability and patched builds.
- Track any affected systems that cannot be updated immediately and escalate them for remediation planning.
Evidence notes
This debrief is based on the supplied CVE description, NVD metadata, and Mozilla reference URLs only. The corpus states the vulnerability is a privilege escalation in the DOM Workers component and identifies the fixed versions. NVD supplies the CVSS vector, CWE-269 mapping, and vulnerable version boundaries. No exploit details or advisory body text were provided.
Official resources
-
CVE-2026-8955 CVE record
CVE.org
-
CVE-2026-8955 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Permissions Required
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Published in the supplied source corpus on 2026-05-19T14:16:51.820Z and modified on 2026-05-20T17:16:29.980Z. The supplied enrichment data does not mark this CVE as KEV-listed.