PatchSiren cyber security CVE debrief
CVE-2026-8957 Mozilla CVE debrief
CVE-2026-8957 is a Mozilla privilege-escalation issue in the Enterprise Policies component. Mozilla fixed it in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. NVD rates the issue 8.8 HIGH and maps it to network-reachable exploitation with user interaction required.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-20
Who should care
Security teams and administrators managing Mozilla Firefox or Thunderbird deployments, especially enterprise and ESR environments, should prioritize this issue. End users on versions older than the fixed releases should update as soon as possible.
Technical summary
The supplied record identifies a privilege escalation in Mozilla’s Enterprise Policies component. NVD lists affected Firefox releases before 151.0 and Firefox ESR before 140.11.0, plus Thunderbird releases before 151.0 and Thunderbird ESR before 140.11. The NVD CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a high-severity issue with no privileges required, low attack complexity, and user interaction required.
Defensive priority
High — patch promptly across Firefox and Thunderbird fleets, with extra attention to enterprise and ESR deployments.
Recommended defensive actions
- Upgrade Firefox to 151 or later, or Firefox ESR to 140.11 or later.
- Upgrade Thunderbird to 151 or later, or Thunderbird ESR to 140.11 or later.
- Verify enterprise policy-managed desktops and mail clients are included in patch coverage.
- Use the referenced Mozilla advisories to confirm remediation guidance and product-specific release notes.
- Track any systems that cannot be updated immediately and place them on a prioritized remediation list.
Evidence notes
This debrief is based on the supplied NVD modified record and its Mozilla references. The record was published on 2026-05-19 and modified on 2026-05-20. NVD provides the affected CPE criteria, CVSS vector, and Mozilla advisory links. No confirmed exploit campaign, KEV listing, or weaponized reproduction was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8957 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8957
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8957 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8957
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-46/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-48/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-50/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-51/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.