These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-2786 is a critical use-after-free vulnerability in Mozilla’s JavaScript Engine component. Mozilla fixed it in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. Based on the NVD CVSS vector, the issue is reachable over the network, requires no privileges, and needs no user interaction, making timely patching important for both browser and mail client deployments.
CVE-2026-2777 is a critical vulnerability in the Messaging System component of Firefox, allowing for privilege escalation. The vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The CVSS score for this vulnerability is 9.8, indicating a high severity. The vulnerability was published on February 24, 2026, and modified on June 30, 2026. The [truncated]
CVE-2026-2776 is a critical vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:26.023Z and last m [truncated]
CVE-2026-2774 is a critical vulnerability in the Audio/Video component of Firefox, caused by an integer overflow. The vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicating a critical severity. The vulnerability was publicly disclosed on February 24 [truncated]
CVE-2026-2772 is a critical use-after-free vulnerability in the Audio/Video: Playback component of Firefox. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE record was published on February 24, 2026, and last modified on June 30, 2026.
A critical vulnerability was found in the DOM: Core & HTML component of Firefox, which could lead to undefined behavior. This issue was addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability's impact on the browser's functionality and potential exploitation pathways should be assessed by defenders to prioritize updates and mitigate risks [truncated]
CVE-2026-2769 is a high-severity vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird, caused by a use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. The CVE record was published on 2026-02-24T14:16:25.28 [truncated]
CVE-2026-2768 is a critical vulnerability in the Storage: IndexedDB component of Mozilla Firefox and Thunderbird, allowing for a sandbox escape. The vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. This vulnerability has a CVSS score of 10 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:25.183Z and last modified on 2026-06-30T03:18:17.470Z.
CVE-2026-2767 is a critical use-after-free vulnerability in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 9.8 and a severity of CRITICAL. The CVE was published on 2026-02-24T14:16:25.080Z and last modified on 2026-06-30T03:18:17.227Z. The vendor, Mozilla, has provided advi [truncated]
CVE-2026-2766 is a critical use-after-free vulnerability in the JavaScript Engine's JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE was published on February 24, 2026, and last modified on June 30, 2026. The vulnerability affects multiple products from Mozill [truncated]
CVE-2026-2763 is a critical use-after-free vulnerability in the JavaScript Engine component of Mozilla Firefox. The vulnerability was publicly disclosed on February 24, 2026, and was modified on June 30, 2026. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. The vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
CVE-2026-2759 is a critical vulnerability in the Mozilla Firefox browser, specifically affecting the Graphics: ImageLib component. The vulnerability was publicly disclosed on February 24, 2026, and has a CVSS score of 9.8, indicating a high severity level. The issue was addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. Users are advised to update to t [truncated]
CVE-2026-2758 is a critical use-after-free vulnerability in the JavaScript: GC component of Mozilla Firefox. The vulnerability was publicly disclosed on February 24, 2026, and was modified on June 30, 2026. It affects multiple versions of Firefox, including Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The CVSS score for this vulnerability is 9.8, indicating a [truncated]
CVE-2026-2757 is a critical vulnerability in the WebRTC: Audio/Video component of Firefox. The vulnerability is caused by incorrect boundary conditions, which can lead to severe consequences. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicati [truncated]
CVE-2026-2447 is a high-severity vulnerability in libvpx, a library used in Mozilla products. The vulnerability is a heap buffer overflow, which can be exploited by attackers to execute arbitrary code. It was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2. Users of these products should update to the latest versions to mitigate the vulnera [truncated]
CVE-2026-24869 is a high-severity vulnerability in the Mozilla Firefox browser. It is a use-after-free issue in the Layout: Scrolling and Overflow component. The vulnerability was publicly disclosed on January 27, 2026, and was modified on June 30, 2026. The issue was fixed in Firefox version 147.0.2. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.8, indicating a high sev [truncated]
CVE-2026-0882 is a high-severity vulnerability in the IPC (Inter-Process Communication) component of Firefox, Thunderbird, and other Mozilla products. This use-after-free vulnerability, patched in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7, could allow attackers to execute arbitrary code. The vulnerability was publicly disclosed on January 13, 2026, and has [truncated]
CVE-2026-0880 is a HIGH severity vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird. The vulnerability is caused by an integer overflow in the Graphics component, which can lead to a sandbox escape. The vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. Users should update to the latest version to mitigate the vulnerability. T [truncated]
CVE-2026-0879 is a critical vulnerability in Mozilla Firefox, allowing for sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE record was published on January 13, 2026, and last m [truncated]
CVE-2026-0878 is a HIGH-severity vulnerability affecting Mozilla products. The issue is a sandbox escape caused by incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. The CVE was published on 2026-01-13 and modified on 2026-06-30. The CVSS score is 8, indicating a high severity level. [truncated]
CVE-2026-0877 is a high-severity vulnerability in Mozilla's Firefox, Firefox ESR, and Thunderbird products. This mitigation bypass issue in the DOM: Security component was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. The vulnerability has a CVSS score of 8.1 and is considered HIGH. It allows attackers to bypass mitigations in the DOM: Security compon [truncated]
CVE-2010-3765 is tracked by CISA as a Known Exploited Vulnerability affecting Mozilla Multiple Products and categorized as a remote code execution issue. In the supplied corpus, the KEV entry and CVE record are both dated 2025-10-06, with remediation due by 2025-10-27. Because only curated metadata is provided here, use Mozilla’s security advisory and the NVD record to confirm affected versions and exact fixes.
CVE-2024-9680 is a Mozilla Firefox use-after-free vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is already associated with known exploitation, it should be treated as urgent for anyone running Firefox in environments where rapid update and mitigation are possible.
CVE-2016-9079 is a Mozilla use-after-free vulnerability affecting Firefox, Firefox ESR, and Thunderbird. In the supplied corpus, CISA includes it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as a patch-priority issue and follow vendor update guidance without delay.
CVE-2015-4495 is a Mozilla Firefox security feature bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is a KEV-listed issue, defenders should treat it as a patching priority and follow the vendor’s update guidance. The provided official metadata does not include a CVSS score or deeper technical detail, so the safest response is to verify exposure and apply the [truncated]
CVE-2019-11708 is described as a sandbox escape vulnerability affecting Mozilla Firefox and Thunderbird. CISA includes it in the Known Exploited Vulnerabilities catalog, so it should be treated as a high-priority remediation item for any environment running these products. The supplied corpus does not provide CVSS data or exploit details, so the safest defensive response is to apply vendor updates and ver [truncated]
CVE-2019-11707 is a Mozilla Firefox and Thunderbird type confusion vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2022-05-23, with remediation due by 2022-06-13. Because CISA treats it as known exploited, organizations should prioritize vendor updates for any affected Firefox or Thunderbird deployments and verify that patched versions are actually in place.
CVE-2013-1690 is recorded by CISA as a known exploited denial-of-service vulnerability affecting Mozilla Firefox and Thunderbird. The supplied corpus does not include root cause, affected version ranges, or exploit details, so remediation guidance should rely on the vendor’s updates and CISA’s KEV priority status.
CVE-2022-26486 is a Mozilla Firefox use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-07. Because it is listed as known to be exploited, defenders should treat this as a high-priority patching item and follow Mozilla’s update guidance without delay.
CVE-2022-26485 is a Mozilla Firefox use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-07. Because it is marked as known exploited, organizations should treat it as a high-priority browser remediation item and apply vendor updates as soon as possible.