PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8957 Mozilla CVE debrief

CVE-2026-8957 is a Mozilla privilege-escalation issue in the Enterprise Policies component. Mozilla fixed it in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. NVD rates the issue 8.8 HIGH and maps it to network-reachable exploitation with user interaction required.

Vendor
Mozilla
Product
Firefox
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-05-20
Advisory published
2026-05-19
Advisory updated
2026-05-20

Who should care

Security teams and administrators managing Mozilla Firefox or Thunderbird deployments, especially enterprise and ESR environments, should prioritize this issue. End users on versions older than the fixed releases should update as soon as possible.

Technical summary

The supplied record identifies a privilege escalation in Mozilla’s Enterprise Policies component. NVD lists affected Firefox releases before 151.0 and Firefox ESR before 140.11.0, plus Thunderbird releases before 151.0 and Thunderbird ESR before 140.11. The NVD CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a high-severity issue with no privileges required, low attack complexity, and user interaction required.

Defensive priority

High — patch promptly across Firefox and Thunderbird fleets, with extra attention to enterprise and ESR deployments.

Recommended defensive actions

  • Upgrade Firefox to 151 or later, or Firefox ESR to 140.11 or later.
  • Upgrade Thunderbird to 151 or later, or Thunderbird ESR to 140.11 or later.
  • Verify enterprise policy-managed desktops and mail clients are included in patch coverage.
  • Use the referenced Mozilla advisories to confirm remediation guidance and product-specific release notes.
  • Track any systems that cannot be updated immediately and place them on a prioritized remediation list.

Evidence notes

This debrief is based on the supplied NVD modified record and its Mozilla references. The record was published on 2026-05-19 and modified on 2026-05-20. NVD provides the affected CPE criteria, CVSS vector, and Mozilla advisory links. No confirmed exploit campaign, KEV listing, or weaponized reproduction was provided in the source corpus.

Official resources

Publicly disclosed on 2026-05-19 and modified on 2026-05-20. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. No KEV enrichment was provided in the supplied corpus.