PatchSiren cyber security CVE debrief
CVE-2026-8961 Mozilla CVE debrief
CVE-2026-8961 is a Mozilla spoofing issue in the Form Autofill component. NVD rates it CVSS 6.5/Medium and ties it to user interaction with high integrity impact. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-23
Who should care
Organizations and users running Mozilla Firefox or Thunderbird on affected versions, especially installations older than Firefox 151 / Firefox ESR 140.11 / Thunderbird 151 / Thunderbird ESR 140.11.
Technical summary
NVD describes this as a spoofing issue in Firefox/Thunderbird Form Autofill and classifies it as CWE-290. The published CVSS vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N, indicating network reachability, no privileges required, required user interaction, and a high integrity impact. NVD’s vulnerable CPE criteria cover Firefox and Thunderbird releases below the fixed versions for both regular and ESR branches.
Defensive priority
Medium: prioritize normal patching cadence, but do not defer if Firefox or Thunderbird are broadly deployed in your environment. The combination of user interaction, browser/email-client exposure, and integrity impact makes timely upgrade appropriate.
Recommended defensive actions
- Upgrade Firefox to 151 or later.
- Upgrade Firefox ESR to 140.11 or later.
- Upgrade Thunderbird to 151 or later.
- Upgrade Thunderbird ESR to 140.11 or later.
- Validate deployed versions across desktop fleets and managed endpoints, including ESR channels.
- Review Mozilla advisories linked from NVD for release-specific remediation details.
- Track any systems unable to update promptly and place them on an accelerated remediation plan.
Evidence notes
The CVE record and NVD entry identify the issue as a spoofing problem in Form Autofill and list Mozilla as the vendor. NVD provides the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N), the CWE-290 weakness classification, and vulnerable CPE criteria showing affected Firefox and Thunderbird branches before the stated fixed versions. The NVD record also references Mozilla Bugzilla and four Mozilla security advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8961 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8961
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8961 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8961
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-46/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-48/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-50/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-51/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.