| CVE-2026-75874 | 10 | critical | mozilla / firefox | Sandbox escape in the Remote Settings Client component. | 18d ago |
| CVE-2026-16367 | 10 | critical | mozilla / firefox | Sandbox escape due to invalid pointer in the Disability Access APIs component. | 46d ago |
| CVE-2026-4725 | 10 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. | 165d ago |
| CVE-2026-4692 | 10 | critical | mozilla / firefox | Sandbox escape in the Responsive Design Mode component. | 165d ago |
| CVE-2026-4689 | 10 | critical | mozilla / firefox | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 165d ago |
| CVE-2026-4688 | 10 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 165d ago |
| CVE-2026-84637 | 9.8 | critical | mozilla / thunderbird | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Win | 4d ago |
| CVE-2026-84143 | 9.8 | critical | mozilla / firefox | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. | 4d ago |
| CVE-2026-84142 | 9.8 | critical | mozilla / firefox | Internally found bugs present in Thunderbird 154. | 4d ago |
| CVE-2026-84141 | 9.8 | critical | mozilla / firefox | Integer overflow in the Graphics: ImageLib component. | 4d ago |
| CVE-2026-84140 | 9.8 | critical | mozilla / firefox | Site isolation issue in the DOM: Navigation component. | 4d ago |
| CVE-2026-84135 | 9.8 | critical | mozilla / firefox mobile | Other issue in Firefox Focus for Android. | 4d ago |
| CVE-2026-84134 | 9.8 | critical | mozilla / firefox | Other issue in the Profile Backup component. | 4d ago |
| CVE-2026-84133 | 9.8 | critical | mozilla / firefox | Site isolation issue in the DOM: Push Subscriptions component. | 4d ago |
| CVE-2026-84129 | 9.8 | critical | mozilla / firefox | Site isolation issue in the DOM: Navigation component. | 4d ago |
| CVE-2026-74990 | 9.8 | critical | mozilla / firefox | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74989 | 9.8 | critical | mozilla / firefox | Internally found bugs present in Thunderbird 153. | 18d ago |
| CVE-2026-74988 | 9.8 | critical | mozilla / firefox | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74987 | 9.8 | critical | mozilla / firefox | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74985 | 9.8 | critical | mozilla / firefox | Privilege escalation in the Enterprise Policies component. | 18d ago |
| CVE-2026-74979 | 9.8 | critical | mozilla / firefox | Mitigation bypass in the Add-ons Manager component. | 18d ago |
| CVE-2026-74964 | 9.8 | critical | mozilla / firefox | Integer overflow in the Graphics component. | 18d ago |
| CVE-2026-74944 | 9.8 | critical | mozilla / firefox | Use-after-free in the DOM: Core & HTML component. | 18d ago |
| CVE-2026-74943 | 9.8 | critical | mozilla / firefox | Use-after-free in the Graphics: ImageLib component. | 18d ago |
| CVE-2026-74940 | 9.8 | critical | mozilla / firefox | Use-after-free in the Graphics: Text component. | 18d ago |
| CVE-2026-74936 | 9.8 | critical | mozilla / firefox | Use-after-free in the JavaScript: WebAssembly component. | 18d ago |
| CVE-2026-16412 | 9.8 | critical | mozilla / firefox | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. | 46d ago |
| CVE-2026-16411 | 9.8 | critical | mozilla / firefox | Memory safety bugs present in Firefox 152. | 46d ago |
| CVE-2026-16410 | 9.8 | critical | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 46d ago |
| CVE-2026-16408 | 9.8 | critical | mozilla / firefox | Integer overflow in the Audio/Video: Playback component. | 46d ago |
| CVE-2026-16407 | 9.8 | critical | mozilla / firefox | Mitigation bypass in the DOM: Service Workers component. | 46d ago |
| CVE-2026-16402 | 9.8 | critical | mozilla / firefox | Integer overflow in the Graphics: ImageLib component. | 46d ago |
| CVE-2026-16395 | 9.8 | critical | mozilla / firefox | Integer overflow in the Audio/Video component. | 46d ago |
| CVE-2026-16389 | 9.8 | critical | mozilla / firefox | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. | 46d ago |
| CVE-2026-16388 | 9.8 | critical | mozilla / firefox | Sandbox escape in the DOM: Networking component. | 46d ago |
| CVE-2026-16387 | 9.8 | critical | mozilla / firefox | Site isolation issue in the Networking component. | 46d ago |
| CVE-2026-16383 | 9.8 | critical | mozilla / firefox | Mitigation bypass in the DOM: Networking component. | 46d ago |
| CVE-2026-16382 | 9.8 | critical | mozilla / firefox | Mitigation bypass in the DOM: Service Workers component. | 46d ago |
| CVE-2026-16377 | 9.8 | critical | mozilla / firefox | Mitigation bypass in the PDF Viewer component. | 46d ago |
| CVE-2026-16375 | 9.8 | critical | mozilla / firefox | Site isolation issue in the Networking: HTTP component. | 46d ago |
| CVE-2026-16369 | 9.8 | critical | mozilla / firefox | Integer overflow in the JavaScript: WebAssembly component. | 46d ago |
| CVE-2026-16368 | 9.8 | critical | mozilla / firefox | Incorrect boundary conditions in the JavaScript: WebAssembly component. | 46d ago |
| CVE-2026-16363 | 9.8 | critical | mozilla / firefox | JIT miscompilation in the JavaScript: WebAssembly component. | 46d ago |
| CVE-2026-16361 | 9.8 | critical | mozilla / firefox | Memory safety bugs present in Thunderbird ESR 140.12. | 46d ago |
| CVE-2026-16360 | 9.8 | critical | mozilla / firefox | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. | 46d ago |
| CVE-2026-16358 | 9.8 | critical | mozilla / firefox | Site isolation issue in the Graphics: WebRender component. | 46d ago |
| CVE-2026-16357 | 9.8 | critical | mozilla / firefox | Incorrect boundary conditions in the Graphics component. | 46d ago |
| CVE-2026-16356 | 9.8 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 46d ago |
| CVE-2026-16355 | 9.8 | critical | mozilla / firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 46d ago |
| CVE-2026-16353 | 9.8 | critical | mozilla / firefox | Invalid pointer in the DOM: Bindings (WebIDL) component. | 46d ago |
| CVE-2026-16352 | 9.8 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 46d ago |
| CVE-2026-16351 | 9.8 | critical | mozilla / firefox | Sandbox escape due to use-after-free in the DOM: Navigation component. | 46d ago |
| CVE-2026-16350 | 9.8 | critical | mozilla / firefox | Incorrect boundary conditions in the Audio/Video: cubeb component. | 46d ago |
| CVE-2026-16349 | 9.8 | critical | mozilla / firefox | Same-origin policy bypass in the DOM: Navigation component. | 46d ago |
| CVE-2026-14241 | 9.8 | critical | mozilla / firefox | Memory safety bugs present in Firefox 152.0.3. | 67d ago |
| CVE-2026-12293 | 9.8 | critical | mozilla / firefox | Use-after-free in the Graphics: WebGPU component. | 81d ago |
| CVE-2026-8956 | 9.8 | critical | mozilla / firefox | Integer overflow in the Networking: JAR component. | 109d ago |
| CVE-2026-8401 | 9.8 | critical | mozilla / firefox | Sandbox escape in the Profile Backup component. | 116d ago |
| CVE-2026-4729 | 9.8 | critical | mozilla / firefox | Memory safety bugs present in Firefox 148 and Thunderbird 148. | 165d ago |
| CVE-2026-4723 | 9.8 | critical | mozilla / firefox | Use-after-free in the JavaScript Engine component. | 165d ago |