LIVE · cybersecurity feed
Live wire
vendor

Mozilla

230 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical104
High125
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-1636710criticalfirefoxSandbox escape due to invalid pointer in the Disability Access APIs component.46d ago
CVE-2026-469210criticalfirefoxSandbox escape in the Responsive Design Mode component.165d ago
CVE-2026-472510criticalfirefoxSandbox escape due to use-after-free in the Graphics: Canvas2D component.165d ago
CVE-2026-468810criticalfirefoxSandbox escape due to use-after-free in the Disability Access APIs component.165d ago
CVE-2026-468910criticalfirefoxSandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component.165d ago
CVE-2026-7587410criticalfirefoxSandbox escape in the Remote Settings Client component.18d ago
CVE-2026-841359.8criticalfirefox mobileOther issue in Firefox Focus for Android.4d ago
CVE-2026-841349.8criticalfirefoxOther issue in the Profile Backup component.4d ago
CVE-2026-841339.8criticalfirefoxSite isolation issue in the DOM: Push Subscriptions component.4d ago
CVE-2026-841299.8criticalfirefoxSite isolation issue in the DOM: Navigation component.4d ago
CVE-2026-163609.8criticalfirefoxMemory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152.46d ago
CVE-2026-122939.8criticalfirefoxUse-after-free in the Graphics: WebGPU component.81d ago
CVE-2026-841429.8criticalfirefoxInternally found bugs present in Thunderbird 154.4d ago
CVE-2026-841419.8criticalfirefoxInteger overflow in the Graphics: ImageLib component.4d ago
CVE-2026-89569.8criticalfirefoxInteger overflow in the Networking: JAR component.109d ago
CVE-2026-841409.8criticalfirefoxSite isolation issue in the DOM: Navigation component.4d ago
CVE-2026-142419.8criticalfirefoxMemory safety bugs present in Firefox 152.0.3.67d ago
CVE-2026-84019.8criticalfirefoxSandbox escape in the Profile Backup component.116d ago
CVE-2026-163589.8criticalfirefoxSite isolation issue in the Graphics: WebRender component.46d ago
CVE-2026-163579.8criticalfirefoxIncorrect boundary conditions in the Graphics component.46d ago
CVE-2026-164029.8criticalfirefoxInteger overflow in the Graphics: ImageLib component.46d ago
CVE-2026-163639.8criticalfirefoxJIT miscompilation in the JavaScript: WebAssembly component.46d ago
CVE-2026-163619.8criticalfirefoxMemory safety bugs present in Thunderbird ESR 140.12.46d ago
CVE-2026-163699.8criticalfirefoxInteger overflow in the JavaScript: WebAssembly component.46d ago
CVE-2026-163689.8criticalfirefoxIncorrect boundary conditions in the JavaScript: WebAssembly component.46d ago
CVE-2026-749909.8criticalfirefoxInternally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153.18d ago
CVE-2026-749899.8criticalfirefoxInternally found bugs present in Thunderbird 153.18d ago
CVE-2026-749889.8criticalfirefoxInternally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153.18d ago
CVE-2026-749879.8criticalfirefoxInternally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153.18d ago
CVE-2026-749859.8criticalfirefoxPrivilege escalation in the Enterprise Policies component.18d ago
CVE-2026-749409.8criticalfirefoxUse-after-free in the Graphics: Text component.18d ago
CVE-2026-749369.8criticalfirefoxUse-after-free in the JavaScript: WebAssembly component.18d ago
CVE-2026-749449.8criticalfirefoxUse-after-free in the DOM: Core & HTML component.18d ago
CVE-2026-846379.8criticalthunderbirdMalicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Win4d ago
CVE-2026-47299.8criticalfirefoxMemory safety bugs present in Firefox 148 and Thunderbird 148.165d ago
CVE-2026-47059.8criticalfirefoxUndefined behavior in the WebRTC: Signaling component.165d ago
CVE-2026-47109.8criticalfirefoxIncorrect boundary conditions in the Audio/Video component.165d ago
CVE-2026-47179.8criticalfirefoxPrivilege escalation in the Netmonitor component.165d ago
CVE-2026-749799.8criticalfirefoxMitigation bypass in the Add-ons Manager component.18d ago
CVE-2026-47209.8criticalfirefoxMemory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148.165d ago
CVE-2026-749439.8criticalfirefoxUse-after-free in the Graphics: ImageLib component.18d ago
CVE-2026-749649.8criticalfirefoxInteger overflow in the Graphics component.18d ago
CVE-2026-164129.8criticalfirefoxMemory safety bugs present in Firefox ESR 140.12 and Firefox 152.46d ago
CVE-2026-47119.8criticalfirefoxUse-after-free in the Widget: Cocoa component.165d ago
CVE-2026-164119.8criticalfirefoxMemory safety bugs present in Firefox 152.46d ago
CVE-2026-164109.8criticalfirefoxJIT miscompilation in the JavaScript Engine: JIT component.46d ago
CVE-2026-164089.8criticalfirefoxInteger overflow in the Audio/Video: Playback component.46d ago
CVE-2026-164079.8criticalfirefoxMitigation bypass in the DOM: Service Workers component.46d ago
CVE-2026-47029.8criticalfirefoxJIT miscompilation in the JavaScript Engine component.165d ago
CVE-2026-163959.8criticalfirefoxInteger overflow in the Audio/Video component.46d ago
CVE-2026-163899.8criticalfirefoxIncorrect boundary conditions, integer overflow in the Libraries component in NSS.46d ago
CVE-2026-163889.8criticalfirefoxSandbox escape in the DOM: Networking component.46d ago
CVE-2026-163879.8criticalfirefoxSite isolation issue in the Networking component.46d ago
CVE-2026-163839.8criticalfirefoxMitigation bypass in the DOM: Networking component.46d ago
CVE-2026-46919.8criticalfirefoxUse-after-free in the CSS Parsing and Computation component.165d ago
CVE-2026-163829.8criticalfirefoxMitigation bypass in the DOM: Service Workers component.46d ago
CVE-2026-163779.8criticalfirefoxMitigation bypass in the PDF Viewer component.46d ago
CVE-2026-46969.8criticalfirefoxUse-after-free in the Layout: Text and Fonts component.165d ago
CVE-2026-163759.8criticalfirefoxSite isolation issue in the Networking: HTTP component.46d ago
CVE-2026-46989.8criticalfirefoxJIT miscompilation in the JavaScript Engine: JIT component.165d ago
CVE-2026-163569.8criticalfirefoxSandbox escape due to use-after-free in the Disability Access APIs component.46d ago
CVE-2026-47009.8criticalfirefoxMitigation bypass in the Networking: HTTP component.165d ago
CVE-2026-47019.8criticalfirefoxUse-after-free in the JavaScript Engine component.165d ago
CVE-2026-47219.8criticalfirefoxMemory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunder165d ago
CVE-2026-163559.8criticalfirefoxJIT miscompilation in the JavaScript Engine: JIT component.46d ago
CVE-2026-47239.8criticalfirefoxUse-after-free in the JavaScript Engine component.165d ago
CVE-2026-841439.8criticalfirefoxInternally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14.4d ago
CVE-2026-163539.8criticalfirefoxInvalid pointer in the DOM: Bindings (WebIDL) component.46d ago
CVE-2026-163529.8criticalfirefoxSandbox escape due to use-after-free in the Disability Access APIs component.46d ago
CVE-2026-163519.8criticalfirefoxSandbox escape due to use-after-free in the DOM: Navigation component.46d ago
CVE-2026-163509.8criticalfirefoxIncorrect boundary conditions in the Audio/Video: cubeb component.46d ago
CVE-2026-163499.8criticalfirefoxSame-origin policy bypass in the DOM: Navigation component.46d ago
CVE-2026-122979.6criticalfirefoxSandbox escape due to incorrect boundary conditions in the Networking component.81d ago
CVE-2026-841219.6criticalfirefoxSandbox escape due to use-after-free in the DOM: Security component.4d ago
CVE-2026-89599.6criticalfirefoxSandbox escape due to incorrect boundary conditions in the Widget: Win32 component.109d ago
CVE-2026-122949.6criticalfirefoxSandbox escape in the DOM: Workers component.81d ago
CVE-2026-89539.6criticalfirefoxSandbox escape due to use-after-free in the Disability Access APIs component.109d ago
CVE-2026-122969.6criticalfirefoxSandbox escape in the Security: Process Sandboxing component.81d ago
CVE-2026-122959.6criticalfirefoxSandbox escape in the DOM: Navigation component.81d ago
CVE-2026-841199.6criticalfirefoxSandbox escape due to use-after-free in the DOM: Navigation component.4d ago
CVE-2026-89509.3criticalfirefoxSame-origin policy bypass in the Networking: HTTP component.109d ago
CVE-2026-749869.1criticalfirefoxSite isolation issue in the CSS Parsing and Computation component.18d ago
CVE-2026-89489.1criticalfirefoxSame-origin policy bypass in the DOM: Networking component.109d ago
CVE-2026-47169.1criticalfirefoxIncorrect boundary conditions, uninitialized memory in the JavaScript Engine component.165d ago
CVE-2026-47159.1criticalfirefoxUninitialized memory in the Graphics: Canvas2D component.165d ago
CVE-2026-47249.1criticalfirefoxUndefined behavior in the Audio/Video component.165d ago
CVE-2026-123049.1criticalfirefoxSame-origin policy bypass in the Networking: Cookies component.81d ago
CVE-2026-123159.1criticalfirefoxMitigation bypass in the DOM: Security component.81d ago
CVE-2026-123169.1criticalfirefoxMitigation bypass in the DOM: Security component.81d ago
CVE-2026-163709.1criticalfirefoxMitigation bypass in the DOM: Networking component.46d ago
CVE-2026-163599.1criticalfirefoxIncorrect boundary conditions in the Audio/Video: GMP component.46d ago
CVE-2026-163649.1criticalfirefoxIncorrect boundary conditions in the Audio/Video: Playback component.46d ago
CVE-2026-163809.1criticalfirefoxMitigation bypass in the Networking component.46d ago
CVE-2026-163819.1criticalfirefoxSame-origin policy bypass in the Networking: DNS component.46d ago
CVE-2026-163909.1criticalfirefoxMitigation bypass in the Enterprise Policies component.46d ago
CVE-2026-163929.1criticalfirefoxJIT miscompilation in the JavaScript Engine: JIT component.46d ago
CVE-2026-163939.1criticalfirefoxIncorrect boundary conditions in the Graphics: WebGPU component.46d ago
CVE-2026-163949.1criticalfirefoxMitigation bypass in the DOM: Security component.46d ago
CVE-2026-164069.1criticalfirefoxMitigation bypass in the Networking component.46d ago
CVE-2026-749619.1criticalfirefoxSide-channel in the Web Audio component.18d ago

Filter the full tracker by Mozilla

Our coverage of Mozilla

breach

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]

patch

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

Audit logs found no unexpected visitors, but release verification still needs an update

security

Mozilla Issues New Firefox GPG Key Following Exposure

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.