PatchSiren cyber security CVE debrief
CVE-2026-8966 Mozilla CVE debrief
CVE-2026-8966 is a Mozilla information disclosure vulnerability in the IP Protection component. According to NVD and Mozilla’s advisories, it affects Firefox and Thunderbird versions before 151.0.0 and was fixed in Firefox 151 and Thunderbird 151. The CVSS 3.1 score is 7.5 (HIGH), reflecting network exposure, no user interaction, and high confidentiality impact.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-20
Who should care
Administrators and users running Mozilla Firefox or Thunderbird, especially on systems that may remain on versions older than 151.0.0. Security teams managing desktop application patching should prioritize this update because the issue affects confidentiality and is reachable over the network without privileges or user interaction.
Technical summary
NVD classifies CVE-2026-8966 as CWE-200 (Information Exposure). The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a network-reachable issue with low attack complexity, no privileges required, no user interaction, and high confidentiality impact. NVD lists vulnerable CPEs for mozilla:firefox and mozilla:thunderbird with affected versions ending before 151.0.0. Mozilla’s referenced advisories and Bugzilla record are the official sources linked from the CVE entry.
Defensive priority
High. This is a high-severity confidentiality issue affecting widely used client software. Patch quickly if Firefox or Thunderbird is deployed in your environment, and confirm all installations are at 151.0.0 or later.
Recommended defensive actions
- Upgrade Firefox to version 151.0.0 or later.
- Upgrade Thunderbird to version 151.0.0 or later.
- Inventory endpoints and confirm no affected Firefox or Thunderbird versions remain below 151.0.0.
- Prioritize patching on devices that handle sensitive email or browsing data.
- Review Mozilla security advisories for any follow-on guidance and verify deployment completion.
Evidence notes
This debrief is based only on the supplied CVE record, NVD metadata, and Mozilla-linked references. The CVE was published on 2026-05-19 and modified on 2026-05-20. NVD lists the vulnerability as analyzed, assigns CWE-200, and records vulnerable Firefox and Thunderbird CPEs ending before 151.0.0. The official references provided are a Mozilla Bugzilla issue and Mozilla security advisories mfsa2026-46 and mfsa2026-50.
Official resources
-
CVE-2026-8966 CVE record
CVE.org
-
CVE-2026-8966 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Permissions Required
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Publicly disclosed on 2026-05-19 14:16:53.043Z and last modified on 2026-05-20 17:51:24.320Z, per the supplied CVE timeline.