Back to search
Mozilla
Firefox
Mozilla web browser focused on open standards and privacy.
153 (ESR)
Switch to this train
Stable
Switch to this train
140 (ESR)
Current train
115 (ESR)
Switch to this train
Current version
140.15.0
- Release date
- September 01, 2026
- Security status
- 100 high-severity CVEs tracked in the last 90 days. Current version impact is unclear.
Source
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 140.15.0 | 2026-09-01 | Release Notes |
| 140.14.0 | 2026-08-18 | Release Notes |
| 140.13.0 | 2026-07-21 | Release Notes |
| 140.12.0 | 2026-06-16 | Release Notes |
| 140.11.0 | 2026-05-19 | Release Notes |
| 140.10.2 | 2026-05-07 | Release Notes |
| 140.10.1 | 2026-04-28 | Release Notes |
| 140.10.0 | 2026-04-21 | Release Notes |
| 140.9.1 | 2026-04-07 | Release Notes |
| 140.9.0 | 2026-03-24 | Release Notes |
| 140.8.0 | 2026-02-24 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-84144 | HIGH (7.5) | 2026-09-01 | Current versionnot affected | Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84143 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
| CVE-2026-84142 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
| CVE-2026-84141 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84140 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84139 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84138 | HIGH (7.5) | 2026-09-01 | Current versionnot affected | Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
| CVE-2026-84137 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84136 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84135 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84134 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84133 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84132 | HIGH (7.5) | 2026-09-01 | Current versionnot affected | Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84130 | HIGH (7.5) | 2026-09-01 | Current versionnot affected | Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84129 | CRITICAL (9.8) | 2026-09-01 | Current versionnot affected | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84128 | HIGH (8.8) | 2026-09-01 | Current versionnot affected | Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
| CVE-2026-84123 | HIGH (8.8) | 2026-09-01 | Current versionnot affected | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
| CVE-2026-84117 | HIGH (8.8) | 2026-09-01 | Current versionnot affected | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. |
| CVE-2026-84145 | HIGH (7.5) | 2026-09-01 | Current versionnot affected | Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
| CVE-2026-84131 | HIGH (8.8) | 2026-09-01 | Current versionnot affected | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
| CVE-2026-84121 | CRITICAL (9.6) | 2026-09-01 | Current versionnot affected | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
| CVE-2026-84119 | CRITICAL (9.6) | 2026-09-01 | Current versionnot affected | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. |
| CVE-2026-74989 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. |
| CVE-2026-74988 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74986 | CRITICAL (9.1) | 2026-08-18 | Current versionnot affected | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74985 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74982 | HIGH (7.5) | 2026-08-18 | Current versionnot affected | Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74981 | HIGH (8.1) | 2026-08-18 | Current versionnot affected | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74979 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74978 | HIGH (8.1) | 2026-08-18 | Current versionnot affected | Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74977 | HIGH (7.5) | 2026-08-18 | Current versionnot affected | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74966 | HIGH (7.5) | 2026-08-18 | Current versionnot affected | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74961 | CRITICAL (9.1) | 2026-08-18 | Current versionnot affected | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74958 | HIGH (7.5) | 2026-08-18 | Current versionnot affected | Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74956 | CRITICAL (9.1) | 2026-08-18 | Current versionnot affected | Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74955 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74954 | HIGH (7.5) | 2026-08-18 | Current versionnot affected | Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74952 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2. |
| CVE-2026-74950 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74947 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74938 | CRITICAL (9.1) | 2026-08-18 | Current versionnot affected | Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-74937 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
| CVE-2026-75874 | CRITICAL (10.0) | 2026-08-18 | Current versionnot affected | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2. |
| CVE-2026-74990 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74987 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74983 | HIGH (8.1) | 2026-08-18 | Current versionnot affected | Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74969 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74965 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74964 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74962 | HIGH (8.1) | 2026-08-18 | Current versionnot affected | Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74960 | HIGH (8.1) | 2026-08-18 | Current versionnot affected | Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74959 | CRITICAL (9.1) | 2026-08-18 | Current versionnot affected | Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74957 | HIGH (8.1) | 2026-08-18 | Current versionnot affected | Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74953 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74949 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74946 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74944 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74943 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74942 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74941 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74940 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74939 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74936 | CRITICAL (9.8) | 2026-08-18 | Current versionnot affected | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74935 | HIGH (8.8) | 2026-08-18 | Current versionnot affected | Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-74934 | HIGH (7.5) | 2026-08-18 | Current versionnot affected | Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. |
| CVE-2026-16361 | CRITICAL (9.8) | 2026-07-21 | Current versionunclear | Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13. |
| CVE-2026-16360 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16412 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16411 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16410 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16409 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16408 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16407 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16406 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16405 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16404 | HIGH (7.4) | 2026-07-21 | Current versionnot affected | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16402 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16401 | HIGH (8.8) | 2026-07-21 | Current versionnot affected | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16400 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16399 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16398 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16396 | HIGH (8.8) | 2026-07-21 | Current versionnot affected | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16395 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16394 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16359 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16393 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16392 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16391 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16390 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16389 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16388 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16387 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16386 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16385 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16384 | HIGH (7.5) | 2026-07-21 | Current versionnot affected | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16383 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16382 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16381 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
| CVE-2026-16380 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16358 | CRITICAL (9.8) | 2026-07-21 | Current versionnot affected | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. |
50 further matching CVEs are not displayed. The table shows the 100 most relevant of 150, recently published first.