PatchSiren

Mozilla CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92044

A high-severity information disclosure vulnerability was found in the Networking: HTTP component of Firefox, affecting multiple products including Firefox, Firefox ESR, and Thunderbird. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. This issue could potentially lead to information disclosure, emphasizing the need for defenders to assess exposure and [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92042

A race condition vulnerability in the DOM: Content Processes component of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR was publicly disclosed. The issue was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. Defenders should verify and apply patches to prevent potential exploitation. This vulnerability requires verification and patching to prevent potential exploita [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92041

A critical vulnerability, CVE-2026-92041, was found in the DOM: Networking component of Firefox and Thunderbird, which could allow for mitigation bypass. This issue was addressed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. The vulnerability's critical severity, with a CVSS score of 9.1, necessitates verification of exposure and assessment of potential impact. Defenders shoul [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92040

A use-after-free vulnerability in the JavaScript: WebAssembly component of Firefox and Thunderbird has been patched. This issue, CVE-2026-92040, was fixed in Firefox 156 and Thunderbird 156. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. The vulnerability affects the WebAssembly component, which is used in Firefox and Thunderbird, and could potentially lead to crashes or code e [truncated]

MEDIUM Mozilla CVE published 2026-09-15

CVE-2026-92039

A mitigation bypass vulnerability exists in the DOM: Notifications component of Firefox, Firefox ESR, and Thunderbird. This issue allows attackers to bypass existing mitigations, potentially leading to further exploitation. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. Defenders should assess exposure and apply patches, especially in environments wh [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92038

A critical vulnerability, CVE-2026-92038, was found in the Remote Settings Client component, which could allow mitigation bypass. This issue was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. The CVSS score is 9.1, indicating a critical severity. The CVE was published on 2026-09-15T13:16:55.180Z and last modified on 2026-09-21T18:17:12.463Z.

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92037

A critical vulnerability was found in the DOM: Animation component of Firefox and Thunderbird, which could lead to high impact attacks if left unpatched. This issue was fixed in Firefox 156 and Thunderbird 156. Defenders should assess exposure and apply patches to prevent potential attacks. The vulnerability has a high CVSS score of 9.8, indicating a critical severity level. It is essential to review syst [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92036

A critical vulnerability was found in the Networking: HTTP component of Firefox and Thunderbird, which could lead to severe consequences such as potential remote code execution. The issue, caused by incorrect boundary conditions, was fixed in Firefox 156 and Thunderbird 156. Defenders and administrators should assess exposure and prioritize updates to prevent potential attacks. The vulnerability's CVSS sc [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92035

A critical vulnerability, CVE-2026-92035, was found in the Graphics component due to incorrect boundary conditions, leading to a sandbox escape. This issue was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. The CVSS score is 9.6, indicating a high severity level. The vulnerability allows for a sandbox escape, which can have significant operational impacts. Defenders shoul [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92034

A site isolation issue in the Graphics component of Firefox and Thunderbird has been patched. This vulnerability, CVE-2026-92034, was fixed in Firefox 156 and Thunderbird 156. The CVSS score is 9.1, indicating critical severity. The issue allows for potential site isolation bypass, which could enable access to sensitive data. Defenders should verify and apply patches immediately to prevent exploitation. T [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92032

A critical vulnerability, CVE-2026-92032, was found in the Graphics component, allowing for a sandbox escape due to an invalid pointer. This issue was fixed in multiple versions of Firefox, Firefox ESR, and Thunderbird. The vulnerability has a CVSS score of 9.6 and is considered critical. The fixes address a sandbox escape vulnerability caused by an invalid pointer in the Graphics component, impacting Fir [truncated]

MEDIUM Mozilla CVE published 2026-09-15

CVE-2026-92031

The CVE-2026-92031 vulnerability is an information disclosure issue in the Graphics: ImageLib component of Firefox and Thunderbird. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. Defenders should assess exposure and apply patches as needed to prevent potential information disclosure. The vulnerability was publ [truncated]

MEDIUM Mozilla CVE published 2026-09-15

CVE-2026-92030

A mitigation bypass vulnerability exists in the DOM: Copy & Paste and Drag & Drop component of Firefox, Firefox ESR, and Thunderbird. This issue was addressed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. The vulnerability allows for potential security risks if exploited. Defenders should verify and apply patches for affected systems, re [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92029

A use-after-free vulnerability in the SVG component of Firefox, Firefox ESR, and Thunderbird has been addressed. The vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. Defenders responsible for managing and securing these installations should prioritize verifying and applying patches to prevent pote [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92028

A use-after-free vulnerability exists in the DOM: Core & HTML component of Firefox. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. The vulnerability could potentially allow an attacker to execute arbitrary code, leading to significant security risks. Defenders should prioritize verifying an [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92027

A use-after-free vulnerability in the DOM: Streams component of Firefox, Firefox ESR, and Thunderbird has been addressed. The vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. This high-severity issue could potentially allow attackers to exploit the affected systems, leading to significant operatio [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92026

A use-after-free vulnerability in the Networking component of Firefox, Firefox ESR, and Thunderbird has been patched. The vulnerability, CVE-2026-92026, was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. Defenders should assess exposure, particularly for systems using these applications.

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92025

A use-after-free vulnerability in the DOM: Navigation component of Firefox, Firefox ESR, and Thunderbird has been addressed. The issue was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. This vulnerability could potentially allow for code execution, making it critical for defenders to assess exposure and apply pat [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92024

A use-after-free vulnerability in the SVG component of Firefox, Firefox ESR, and Thunderbird has been patched. The vulnerability, CVE-2026-92024, was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. Defenders should assess exposure, particularly for systems using affected versions.

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92023

A use-after-free vulnerability in the XML component of Firefox, Firefox ESR, and Thunderbird has been patched. The vulnerability, CVE-2026-92023, was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. This high-severity issue could potentially allow attackers to execute arbitrary code, making it crucial for defenders [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92022

A use-after-free vulnerability exists in the DOM: HTML Parser component of Firefox, which was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. This issue has a CVSS score of 8.8 and is considered HIGH severity. The vulnerability affects the Firefox and Thunderbird products, and defenders should prioritize verifying [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92021

A use-after-free vulnerability in the JavaScript Engine's JIT component was fixed in Firefox ESR 140.16 and Thunderbird 140.16. This vulnerability could potentially allow for code execution on affected systems. Defenders should assess exposure, particularly for systems using these products, and prioritize updating to the fixed versions. The vulnerability was reported by [email protected] and fixed in F [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92019

A mitigation bypass vulnerability in the Remote Settings Client component of Firefox, Firefox ESR, and Thunderbird was fixed in multiple versions. The CVE record was published on 2026-09-15T13:16:51.677Z and was last modified on 2026-09-21T17:19:15.793Z. Defenders should assess exposure and apply patches, especially in environments utilizing the Remote Settings Client. This vulnerability allows for potent [truncated]

CRITICAL Mozilla CVE published 2026-09-15

CVE-2026-92018

A sandbox escape vulnerability in the DOM: Core & HTML component of Firefox, Firefox ESR, and Thunderbird was fixed in multiple versions. The CVE record was published on 2026-09-15T13:16:51.540Z and was last modified on 2026-09-20T01:16:34.680Z. The NVD entry is currently Awaiting Analysis. This vulnerability has a CVSS score of 9.6 and a severity of CRITICAL. Defenders should prioritize verifying and app [truncated]

HIGH Mozilla CVE published 2026-09-15

CVE-2026-92016

A use-after-free vulnerability exists in the Disability Access APIs component of Firefox, Firefox ESR, and Thunderbird. This issue was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. The vulnerability allows for potential exploitation, which could lead to security risks if not addressed. Defenders should assess exposure and apply pat [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84642

CVE-2026-84642 debrief based on the supplied source corpus. The vulnerability in Mozilla Thunderbird allows unintended hostnames to match and serve remote attachments due to unescaped values in the mail.allowed_attachment_hostnames advanced config setting. This issue was fixed in Thunderbird 155 and Thunderbird 153.2. Defenders should assess exposure and potential impact, focusing on email attachment hand [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84641

CVE-2026-84641 is a high-severity vulnerability in Thunderbird that can lead to use-after-free and heap-memory disclosure. A malicious IMAP server can trigger this vulnerability by sending a crafted ID response. This can result in heap contents being persisted to prefs.js. The vulnerability was fixed in Thunderbird 155, 140.15, and 153.2. Defenders should prioritize verifying exposure, assessing upgrade f [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84640

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. The vulnerability allows for a one-byte read past the end of a buffer, which could potentially lead to information disclosure. However, there is no evidence of this vulnerability being exploited in the wild. Users of Thund [truncated]

CRITICAL Mozilla CVE published 2026-09-01

CVE-2026-84637

Thunderbird users should assess exposure to malicious calendar invitations with file URI attachments, particularly with the new invitation display enabled. Defenders must verify if systems or users have opened such invitations. Mozilla has released Thunderbird 154 and Thunderbird 153.2 to address this vulnerability, emphasizing the need for immediate patching and exposure verification. Users on Windows ar [truncated]

HIGH Mozilla CVE published 2026-09-01

CVE-2026-84144

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T13:20:08.563Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Mozilla Thunderbird, specifically versions 154 and Thunderbird ESR 153.1, which contain multiple bugs that could lead to memory corruption or other security defects. These bugs were [truncated]