PatchSiren

Mozilla CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8963

CVE-2026-8963 is a Mozilla Web Speech spoofing vulnerability affecting Firefox and Thunderbird versions before 151.0.0. Mozilla’s fixes are reflected in Firefox 151 and Thunderbird 151, and NVD rates the issue High with a CVSS 3.1 score of 7.5.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8962

CVE-2026-8962 is a Mozilla vulnerability described by NVD as a mitigation bypass in the DOM: Security component. NVD rates it 8.1 HIGH with a CVSS vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N and maps it to CWE-693. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird ESR 140.11. Because exploitation requires user interaction but can affect confidentiality and inte [truncated]

MEDIUM Mozilla CVE published 2026-05-19

CVE-2026-8961

CVE-2026-8961 is a Mozilla spoofing issue in the Form Autofill component. NVD rates it CVSS 6.5/Medium and ties it to user interaction with high integrity impact. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8960

CVE-2026-8960 is a high-severity spoofing issue in Mozilla WebExtensions. Mozilla states the issue was fixed in Firefox 151 and Thunderbird 151. NVD rates the issue at CVSS 7.5 with network attack vector, no privileges required, no user interaction, and high integrity impact.

CRITICAL Mozilla CVE published 2026-05-19

CVE-2026-8959

CVE-2026-8959 is a critical Mozilla sandbox-escape vulnerability in the Widget: Win32 component. NVD assigns a 9.6 CVSS score and a vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, indicating a network-reachable issue that requires user interaction and can have high impact once triggered. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8958

CVE-2026-8958 is a high-severity Mozilla vulnerability affecting the Security: Process Sandboxing component. According to the CVE record, it can lead to information disclosure and sandbox escape. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8957

CVE-2026-8957 is a Mozilla privilege-escalation issue in the Enterprise Policies component. Mozilla fixed it in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. NVD rates the issue 8.8 HIGH and maps it to network-reachable exploitation with user interaction required.

CRITICAL Mozilla CVE published 2026-05-19

CVE-2026-8956

CVE-2026-8956 is a critical integer overflow in Mozilla’s Networking: JAR component. Mozilla fixed it in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11; the CVSS 3.1 vector indicates network reachability, no privileges, no user interaction, and high impact.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8955

CVE-2026-8955 is a Mozilla privilege-escalation issue in the DOM Workers component. NVD rates it 8.8 HIGH with a network-reachable attack path that requires user interaction. Mozilla fixed the issue in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird ESR 140.11. The supplied corpus does not include the full advisory text, so the most reliable details here come from the CVE record, NVD met [truncated]

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8954

CVE-2026-8954 is a HIGH-severity Mozilla vulnerability in the Audio/Video component involving incorrect boundary conditions and an integer overflow (CWE-119). NVD rates it 7.5 with a network-reachable, no-auth, no-interaction CVSS vector, and Mozilla says it is fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

CRITICAL Mozilla CVE published 2026-05-19

CVE-2026-8953

CVE-2026-8953 is a critical Mozilla vulnerability involving a use-after-free in the Disability Access APIs component. Mozilla states it was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. Because the flaw can lead to sandbox escape and carries a CVSS 3.1 score of 9.6, it should be treated as an urgent patching priority for browsers and mail clients st [truncated]

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8952

CVE-2026-8952 is a high-severity privilege escalation vulnerability in Mozilla’s Application Update component. Mozilla fixed the issue in Firefox 151 and Thunderbird 151. The NVD record rates the issue as network-reachable with user interaction required, and lists affected Firefox and Thunderbird versions below 151.0.0.

MEDIUM Mozilla CVE published 2026-05-19

CVE-2026-8951

CVE-2026-8951 is a medium-severity spoofing issue affecting the Toolbar component in Firefox for Android. Mozilla states the issue was fixed in Firefox 151. Based on the NVD record, the flaw is exposed remotely, requires user interaction, and primarily impacts integrity rather than confidentiality or availability.

CRITICAL Mozilla CVE published 2026-05-19

CVE-2026-8950

CVE-2026-8950 is a critical Mozilla vulnerability publicly disclosed in the CVE/NVD record on 2026-05-19. NVD describes it as a same-origin policy bypass in the Networking: HTTP component. The published severity is CVSS 9.3 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), meaning a remote attacker can potentially exploit it with user interaction and impact cross-origin confidentiality and integrity. The official re [truncated]

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8949

CVE-2026-8949 is an integer overflow in Mozilla's Widget: Win32 component. Mozilla fixed it in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. NVD rates the issue CVSS 7.5 (HIGH) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which points to a remotely reachable availability impact without privileges or user interaction.

CRITICAL Mozilla CVE published 2026-05-19

CVE-2026-8948

CVE-2026-8948 is a critical Mozilla vulnerability involving a same-origin policy bypass in the DOM: Networking component. According to NVD, it affects Firefox and Thunderbird versions before 151.0.0, with high confidentiality and integrity impact and no attack complexity or user interaction required. Mozilla states the issue was fixed in Firefox 151 and Thunderbird 151. Because same-origin policy protecti [truncated]

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8947

CVE-2026-8947 is a Mozilla use-after-free vulnerability in the DOM: Bindings (WebIDL) component. Mozilla states it was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. NVD rates the issue CVSS 3.1 7.3 (HIGH) with network attack vector and no privileges or user interaction required.

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8946

Mozilla disclosed a high-severity boundary-condition issue in the Audio/Video: Web Codecs component affecting Firefox and Thunderbird release lines. The NVD record rates the issue CVSS 3.1 7.5 HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), which indicates a remotely reachable flaw with no privileges or user interaction required and a confidentiality impact. Mozilla states the vulnerability was fixed in Firef [truncated]

HIGH Mozilla CVE published 2026-05-19

CVE-2026-8945

CVE-2026-8945 is a high-severity sandbox escape affecting Firefox and Firefox Focus for Android. The supplied record says the issue was fixed in Firefox 151, and NVD lists the vulnerability as awaiting analysis. The available evidence points to Mozilla security references, including a Bugzilla report and the Mozilla advisory MFSA2026-46. From a defensive standpoint, this is important because a sandbox esc [truncated]

CRITICAL Mozilla CVE published 2026-05-12

CVE-2026-8401

A critical sandbox escape vulnerability in Mozilla Firefox's Profile Backup component allows remote attackers to bypass security boundaries without user interaction. The flaw, rated CVSS 9.8, enables complete compromise of confidentiality, integrity, and availability. Mozilla has released patches across multiple product lines: Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11 [truncated]

HIGH Mozilla CVE published 2026-05-12

CVE-2026-8389

CVE-2026-8389 is a HIGH severity vulnerability in Mozilla Firefox, with a CVSS score of 8.8. The vulnerability is caused by a JIT miscompilation in the JavaScript Engine. This issue was fixed in Firefox 150.0.3. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-8389) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-8389).

MEDIUM Mozilla CVE published 2026-05-12

CVE-2026-8388

CVE-2026-8388 is a medium-severity vulnerability (CVSS 6.5) in Mozilla's JavaScript Engine: JIT component, caused by incorrect boundary conditions. The vulnerability was published on May 12, 2026, and last modified on May 19, 2026. It affects Firefox versions prior to 150.0.3, Firefox ESR versions prior to 115.36 and 140.11, and Thunderbird versions prior to 140.11. The weakness is classified as CWE-119 ( [truncated]

HIGH Mozilla CVE published 2026-05-07

CVE-2026-8093

CVE-2026-8093 is a high-severity memory safety vulnerability affecting Mozilla Firefox 150.0.1 and Thunderbird 150.0.1, published on 2026-05-07 and last modified on 2026-05-18. The vulnerability encompasses multiple memory safety bugs with evidence of memory corruption; Mozilla presumes that with sufficient effort, these could be exploited to achieve arbitrary code execution. The CVSS 3.1 score of 8.1 ref [truncated]

HIGH Mozilla CVE published 2026-05-07

CVE-2026-8092

CVE-2026-8092 documents multiple memory safety bugs in Mozilla Firefox and Thunderbird that could enable arbitrary code execution. The vulnerability affects Firefox ESR 115.35.1, Firefox ESR 140.10.1, Firefox 150.0.1, and corresponding Thunderbird versions. Mozilla's advisory notes that some bugs showed evidence of memory corruption, and with sufficient effort, exploitation for arbitrary code execution wa [truncated]

CRITICAL Mozilla CVE published 2026-05-07

CVE-2026-8091

CVE-2026-8091 is a critical vulnerability in Mozilla Firefox and Thunderbird, with a CVSS score of 9.8. The vulnerability is caused by incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2. The vulnerability was published on May 7, 2026, and modified on June 30 [truncated]

HIGH Mozilla CVE published 2026-04-28

CVE-2026-7323

CVE-2026-7323 is a high-severity vulnerability in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0, involving memory safety bugs that could lead to arbitrary code execution. The bugs showed evidence of memory corruption, and it is presumed that with enough effort, some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbi [truncated]

HIGH Mozilla CVE published 2026-04-28

CVE-2026-7322

CVE-2026-7322 is a high-severity vulnerability affecting Thunderbird ESR 140.10.0, Thunderbird 150.0.0, and other Mozilla products. The vulnerability involves memory safety bugs that could lead to memory corruption and potentially allow attackers to execute arbitrary code. The issue was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. Thi [truncated]

HIGH Mozilla CVE published 2026-04-28

CVE-2026-7320

CVE-2026-7320 is a high-severity vulnerability in the Audio/Video component of Firefox and Thunderbird, allowing for information disclosure. The vulnerability was caused by incorrect boundary conditions and was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1. The CVE was published on 2026-04-28 and last modified on 2026-06-30. The vulnera [truncated]

HIGH Mozilla CVE published 2026-04-26

CVE-2026-6786

CVE-2026-6786 is a memory safety vulnerability affecting Mozilla Firefox and Thunderbird. The issue encompasses multiple memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149, and Thunderbird 149. Mozilla's advisory indicates that some of these bugs demonstrated evidence of memory corruption, and with sufficient effort, exploitation for arbitrary code execution is presumed po [truncated]

HIGH Mozilla CVE published 2026-04-21

CVE-2026-6751

CVE-2026-6751 is a HIGH severity vulnerability in the Audio/Video: Web Codecs component of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The vulnerability was publicly disclosed on April 21, 2026, and has a CVSS score of 7.3. The issue was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The vulnerability allows for potential exploitation of uninitialized memory [truncated]