PatchSiren cyber security CVE debrief
CVE-2026-8957 Mozilla CVE debrief
CVE-2026-8957 is a Mozilla privilege-escalation issue in the Enterprise Policies component. Mozilla fixed it in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. NVD rates the issue 8.8 HIGH and maps it to network-reachable exploitation with user interaction required.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-20
Who should care
Security teams and administrators managing Mozilla Firefox or Thunderbird deployments, especially enterprise and ESR environments, should prioritize this issue. End users on versions older than the fixed releases should update as soon as possible.
Technical summary
The supplied record identifies a privilege escalation in Mozilla’s Enterprise Policies component. NVD lists affected Firefox releases before 151.0 and Firefox ESR before 140.11.0, plus Thunderbird releases before 151.0 and Thunderbird ESR before 140.11. The NVD CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a high-severity issue with no privileges required, low attack complexity, and user interaction required.
Defensive priority
High — patch promptly across Firefox and Thunderbird fleets, with extra attention to enterprise and ESR deployments.
Recommended defensive actions
- Upgrade Firefox to 151 or later, or Firefox ESR to 140.11 or later.
- Upgrade Thunderbird to 151 or later, or Thunderbird ESR to 140.11 or later.
- Verify enterprise policy-managed desktops and mail clients are included in patch coverage.
- Use the referenced Mozilla advisories to confirm remediation guidance and product-specific release notes.
- Track any systems that cannot be updated immediately and place them on a prioritized remediation list.
Evidence notes
This debrief is based on the supplied NVD modified record and its Mozilla references. The record was published on 2026-05-19 and modified on 2026-05-20. NVD provides the affected CPE criteria, CVSS vector, and Mozilla advisory links. No confirmed exploit campaign, KEV listing, or weaponized reproduction was provided in the source corpus.
Official resources
-
CVE-2026-8957 CVE record
CVE.org
-
CVE-2026-8957 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Permissions Required
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Publicly disclosed on 2026-05-19 and modified on 2026-05-20. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. No KEV enrichment was provided in the supplied corpus.