| CVE-2026-16367 | 10 | critical | firefox | Sandbox escape due to invalid pointer in the Disability Access APIs component. | 46d ago |
| CVE-2026-4692 | 10 | critical | firefox | Sandbox escape in the Responsive Design Mode component. | 165d ago |
| CVE-2026-4725 | 10 | critical | firefox | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. | 165d ago |
| CVE-2026-4688 | 10 | critical | firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 165d ago |
| CVE-2026-4689 | 10 | critical | firefox | Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. | 165d ago |
| CVE-2026-75874 | 10 | critical | firefox | Sandbox escape in the Remote Settings Client component. | 18d ago |
| CVE-2026-84135 | 9.8 | critical | firefox mobile | Other issue in Firefox Focus for Android. | 4d ago |
| CVE-2026-84134 | 9.8 | critical | firefox | Other issue in the Profile Backup component. | 4d ago |
| CVE-2026-84133 | 9.8 | critical | firefox | Site isolation issue in the DOM: Push Subscriptions component. | 4d ago |
| CVE-2026-84129 | 9.8 | critical | firefox | Site isolation issue in the DOM: Navigation component. | 4d ago |
| CVE-2026-16360 | 9.8 | critical | firefox | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. | 46d ago |
| CVE-2026-12293 | 9.8 | critical | firefox | Use-after-free in the Graphics: WebGPU component. | 81d ago |
| CVE-2026-84142 | 9.8 | critical | firefox | Internally found bugs present in Thunderbird 154. | 4d ago |
| CVE-2026-84141 | 9.8 | critical | firefox | Integer overflow in the Graphics: ImageLib component. | 4d ago |
| CVE-2026-8956 | 9.8 | critical | firefox | Integer overflow in the Networking: JAR component. | 109d ago |
| CVE-2026-84140 | 9.8 | critical | firefox | Site isolation issue in the DOM: Navigation component. | 4d ago |
| CVE-2026-14241 | 9.8 | critical | firefox | Memory safety bugs present in Firefox 152.0.3. | 67d ago |
| CVE-2026-8401 | 9.8 | critical | firefox | Sandbox escape in the Profile Backup component. | 116d ago |
| CVE-2026-16358 | 9.8 | critical | firefox | Site isolation issue in the Graphics: WebRender component. | 46d ago |
| CVE-2026-16357 | 9.8 | critical | firefox | Incorrect boundary conditions in the Graphics component. | 46d ago |
| CVE-2026-16402 | 9.8 | critical | firefox | Integer overflow in the Graphics: ImageLib component. | 46d ago |
| CVE-2026-16363 | 9.8 | critical | firefox | JIT miscompilation in the JavaScript: WebAssembly component. | 46d ago |
| CVE-2026-16361 | 9.8 | critical | firefox | Memory safety bugs present in Thunderbird ESR 140.12. | 46d ago |
| CVE-2026-16369 | 9.8 | critical | firefox | Integer overflow in the JavaScript: WebAssembly component. | 46d ago |
| CVE-2026-16368 | 9.8 | critical | firefox | Incorrect boundary conditions in the JavaScript: WebAssembly component. | 46d ago |
| CVE-2026-74990 | 9.8 | critical | firefox | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74989 | 9.8 | critical | firefox | Internally found bugs present in Thunderbird 153. | 18d ago |
| CVE-2026-74988 | 9.8 | critical | firefox | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74987 | 9.8 | critical | firefox | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. | 18d ago |
| CVE-2026-74985 | 9.8 | critical | firefox | Privilege escalation in the Enterprise Policies component. | 18d ago |
| CVE-2026-74940 | 9.8 | critical | firefox | Use-after-free in the Graphics: Text component. | 18d ago |
| CVE-2026-74936 | 9.8 | critical | firefox | Use-after-free in the JavaScript: WebAssembly component. | 18d ago |
| CVE-2026-74944 | 9.8 | critical | firefox | Use-after-free in the DOM: Core & HTML component. | 18d ago |
| CVE-2026-84637 | 9.8 | critical | thunderbird | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Win | 4d ago |
| CVE-2026-4729 | 9.8 | critical | firefox | Memory safety bugs present in Firefox 148 and Thunderbird 148. | 165d ago |
| CVE-2026-4705 | 9.8 | critical | firefox | Undefined behavior in the WebRTC: Signaling component. | 165d ago |
| CVE-2026-4710 | 9.8 | critical | firefox | Incorrect boundary conditions in the Audio/Video component. | 165d ago |
| CVE-2026-4717 | 9.8 | critical | firefox | Privilege escalation in the Netmonitor component. | 165d ago |
| CVE-2026-74979 | 9.8 | critical | firefox | Mitigation bypass in the Add-ons Manager component. | 18d ago |
| CVE-2026-4720 | 9.8 | critical | firefox | Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. | 165d ago |
| CVE-2026-74943 | 9.8 | critical | firefox | Use-after-free in the Graphics: ImageLib component. | 18d ago |
| CVE-2026-74964 | 9.8 | critical | firefox | Integer overflow in the Graphics component. | 18d ago |
| CVE-2026-16412 | 9.8 | critical | firefox | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. | 46d ago |
| CVE-2026-4711 | 9.8 | critical | firefox | Use-after-free in the Widget: Cocoa component. | 165d ago |
| CVE-2026-16411 | 9.8 | critical | firefox | Memory safety bugs present in Firefox 152. | 46d ago |
| CVE-2026-16410 | 9.8 | critical | firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 46d ago |
| CVE-2026-16408 | 9.8 | critical | firefox | Integer overflow in the Audio/Video: Playback component. | 46d ago |
| CVE-2026-16407 | 9.8 | critical | firefox | Mitigation bypass in the DOM: Service Workers component. | 46d ago |
| CVE-2026-4702 | 9.8 | critical | firefox | JIT miscompilation in the JavaScript Engine component. | 165d ago |
| CVE-2026-16395 | 9.8 | critical | firefox | Integer overflow in the Audio/Video component. | 46d ago |
| CVE-2026-16389 | 9.8 | critical | firefox | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. | 46d ago |
| CVE-2026-16388 | 9.8 | critical | firefox | Sandbox escape in the DOM: Networking component. | 46d ago |
| CVE-2026-16387 | 9.8 | critical | firefox | Site isolation issue in the Networking component. | 46d ago |
| CVE-2026-16383 | 9.8 | critical | firefox | Mitigation bypass in the DOM: Networking component. | 46d ago |
| CVE-2026-4691 | 9.8 | critical | firefox | Use-after-free in the CSS Parsing and Computation component. | 165d ago |
| CVE-2026-16382 | 9.8 | critical | firefox | Mitigation bypass in the DOM: Service Workers component. | 46d ago |
| CVE-2026-16377 | 9.8 | critical | firefox | Mitigation bypass in the PDF Viewer component. | 46d ago |
| CVE-2026-4696 | 9.8 | critical | firefox | Use-after-free in the Layout: Text and Fonts component. | 165d ago |
| CVE-2026-16375 | 9.8 | critical | firefox | Site isolation issue in the Networking: HTTP component. | 46d ago |
| CVE-2026-4698 | 9.8 | critical | firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 165d ago |
| CVE-2026-16356 | 9.8 | critical | firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 46d ago |
| CVE-2026-4700 | 9.8 | critical | firefox | Mitigation bypass in the Networking: HTTP component. | 165d ago |
| CVE-2026-4701 | 9.8 | critical | firefox | Use-after-free in the JavaScript Engine component. | 165d ago |
| CVE-2026-4721 | 9.8 | critical | firefox | Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunder | 165d ago |
| CVE-2026-16355 | 9.8 | critical | firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 46d ago |
| CVE-2026-4723 | 9.8 | critical | firefox | Use-after-free in the JavaScript Engine component. | 165d ago |
| CVE-2026-84143 | 9.8 | critical | firefox | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. | 4d ago |
| CVE-2026-16353 | 9.8 | critical | firefox | Invalid pointer in the DOM: Bindings (WebIDL) component. | 46d ago |
| CVE-2026-16352 | 9.8 | critical | firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 46d ago |
| CVE-2026-16351 | 9.8 | critical | firefox | Sandbox escape due to use-after-free in the DOM: Navigation component. | 46d ago |
| CVE-2026-16350 | 9.8 | critical | firefox | Incorrect boundary conditions in the Audio/Video: cubeb component. | 46d ago |
| CVE-2026-16349 | 9.8 | critical | firefox | Same-origin policy bypass in the DOM: Navigation component. | 46d ago |
| CVE-2026-12297 | 9.6 | critical | firefox | Sandbox escape due to incorrect boundary conditions in the Networking component. | 81d ago |
| CVE-2026-84121 | 9.6 | critical | firefox | Sandbox escape due to use-after-free in the DOM: Security component. | 4d ago |
| CVE-2026-8959 | 9.6 | critical | firefox | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. | 109d ago |
| CVE-2026-12294 | 9.6 | critical | firefox | Sandbox escape in the DOM: Workers component. | 81d ago |
| CVE-2026-8953 | 9.6 | critical | firefox | Sandbox escape due to use-after-free in the Disability Access APIs component. | 109d ago |
| CVE-2026-12296 | 9.6 | critical | firefox | Sandbox escape in the Security: Process Sandboxing component. | 81d ago |
| CVE-2026-12295 | 9.6 | critical | firefox | Sandbox escape in the DOM: Navigation component. | 81d ago |
| CVE-2026-84119 | 9.6 | critical | firefox | Sandbox escape due to use-after-free in the DOM: Navigation component. | 4d ago |
| CVE-2026-8950 | 9.3 | critical | firefox | Same-origin policy bypass in the Networking: HTTP component. | 109d ago |
| CVE-2026-74986 | 9.1 | critical | firefox | Site isolation issue in the CSS Parsing and Computation component. | 18d ago |
| CVE-2026-8948 | 9.1 | critical | firefox | Same-origin policy bypass in the DOM: Networking component. | 109d ago |
| CVE-2026-4716 | 9.1 | critical | firefox | Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. | 165d ago |
| CVE-2026-4715 | 9.1 | critical | firefox | Uninitialized memory in the Graphics: Canvas2D component. | 165d ago |
| CVE-2026-4724 | 9.1 | critical | firefox | Undefined behavior in the Audio/Video component. | 165d ago |
| CVE-2026-12304 | 9.1 | critical | firefox | Same-origin policy bypass in the Networking: Cookies component. | 81d ago |
| CVE-2026-12315 | 9.1 | critical | firefox | Mitigation bypass in the DOM: Security component. | 81d ago |
| CVE-2026-12316 | 9.1 | critical | firefox | Mitigation bypass in the DOM: Security component. | 81d ago |
| CVE-2026-16370 | 9.1 | critical | firefox | Mitigation bypass in the DOM: Networking component. | 46d ago |
| CVE-2026-16359 | 9.1 | critical | firefox | Incorrect boundary conditions in the Audio/Video: GMP component. | 46d ago |
| CVE-2026-16364 | 9.1 | critical | firefox | Incorrect boundary conditions in the Audio/Video: Playback component. | 46d ago |
| CVE-2026-16380 | 9.1 | critical | firefox | Mitigation bypass in the Networking component. | 46d ago |
| CVE-2026-16381 | 9.1 | critical | firefox | Same-origin policy bypass in the Networking: DNS component. | 46d ago |
| CVE-2026-16390 | 9.1 | critical | firefox | Mitigation bypass in the Enterprise Policies component. | 46d ago |
| CVE-2026-16392 | 9.1 | critical | firefox | JIT miscompilation in the JavaScript Engine: JIT component. | 46d ago |
| CVE-2026-16393 | 9.1 | critical | firefox | Incorrect boundary conditions in the Graphics: WebGPU component. | 46d ago |
| CVE-2026-16394 | 9.1 | critical | firefox | Mitigation bypass in the DOM: Security component. | 46d ago |
| CVE-2026-16406 | 9.1 | critical | firefox | Mitigation bypass in the Networking component. | 46d ago |
| CVE-2026-74961 | 9.1 | critical | firefox | Side-channel in the Web Audio component. | 18d ago |