PatchSiren cyber security CVE debrief
CVE-2026-8966 Mozilla CVE debrief
CVE-2026-8966 is a Mozilla information disclosure vulnerability in the IP Protection component. According to NVD and Mozilla’s advisories, it affects Firefox and Thunderbird versions before 151.0.0 and was fixed in Firefox 151 and Thunderbird 151. The CVSS 3.1 score is 7.5 (HIGH), reflecting network exposure, no user interaction, and high confidentiality impact.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-23
Who should care
Administrators and users running Mozilla Firefox or Thunderbird, especially on systems that may remain on versions older than 151.0.0. Security teams managing desktop application patching should prioritize this update because the issue affects confidentiality and is reachable over the network without privileges or user interaction.
Technical summary
NVD classifies CVE-2026-8966 as CWE-200 (Information Exposure). The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a network-reachable issue with low attack complexity, no privileges required, no user interaction, and high confidentiality impact. NVD lists vulnerable CPEs for mozilla:firefox and mozilla:thunderbird with affected versions ending before 151.0.0. Mozilla’s referenced advisories and Bugzilla record are the official sources linked from the CVE entry.
Defensive priority
High. This is a high-severity confidentiality issue affecting widely used client software. Patch quickly if Firefox or Thunderbird is deployed in your environment, and confirm all installations are at 151.0.0 or later.
Recommended defensive actions
- Upgrade Firefox to version 151.0.0 or later.
- Upgrade Thunderbird to version 151.0.0 or later.
- Inventory endpoints and confirm no affected Firefox or Thunderbird versions remain below 151.0.0.
- Prioritize patching on devices that handle sensitive email or browsing data.
- Review Mozilla security advisories for any follow-on guidance and verify deployment completion.
Evidence notes
This debrief is based only on the supplied CVE record, NVD metadata, and Mozilla-linked references. The CVE was published on 2026-05-19 and modified on 2026-05-20. NVD lists the vulnerability as analyzed, assigns CWE-200, and records vulnerable Firefox and Thunderbird CPEs ending before 151.0.0. The official references provided are a Mozilla Bugzilla issue and Mozilla security advisories mfsa2026-46 and mfsa2026-50.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8966 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8966
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8966 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8966
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-46/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-50/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.