[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Mozilla Firefox, Firefox ESR and Thunderbird to elevate privileges, bypass security measures, disclose confidential information, perform spoofing or clickjacking attacks, or cause denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities allow attackers to elevate privileges, bypass security measures, disclose information, perform spoofing or clickjacking, or cause denial-of-service.
- Who is affected
- All users of Firefox, Firefox ESR, and Thunderbird.
- Urgency
- High severity requires prompt patching; currently not known to be exploited in the wild.
- Action
- Update to the latest patched version of Firefox, Firefox ESR, or Thunderbird.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firefox
Get an email when a new Firefox advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2911
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-749340.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749350.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749360.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749370.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749380.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749390.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749400.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749410.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749420.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749430.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
+10 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMozilla Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Mozilla products (August 19, 2026)cert-fr-avis
- unknownDSA-6451-1 firefox-esr - security updatedebian
- criticalCVE-2026-75874: Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefo…nvd
- criticalCVE-2026-74990: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird…nvd
- unknownCVE-2026-74989: Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory…nvd
- unknownCVE-2026-74988: Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs…nvd
- criticalCVE-2026-74987: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird…nvd
- unknownCVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixe…nvd
- unknownCVE-2026-74985: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Fir…nvd
- unknownCVE-2026-74984: Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154…nvd
- highCVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firef…nvd
Recent advisories for Mozilla Firefox
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilitiescert-bund · 2026-08-18
- medium[NEW] [medium] Mozilla Firefox: Multiple vulnerabilities allow unspecified attackcert-bund · 2026-08-17
- high[UPDATE] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple vulnerabilitiescert-bund · 2026-08-17
- medium[NEW] [medium] Mozilla Firefox for Android: Vulnerability Enables Information Disclosurecert-bund · 2026-08-05
- unknownMozilla Firefox Information Disclosure Vulnerabilityhkcert · 2026-08-05
- unknownVulnerability in Mozilla Firefox for Android (August 5, 2026)cert-fr-avis · 2026-08-05
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Joomla: Multiple vulnerabilities2026-08-19
- medium[NEW] [medium] Axis Axis OS: Multiple vulnerabilities2026-08-19
- medium[NEW] [medium] CPython: Multiple vulnerabilities2026-08-19
- high[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…2026-08-19
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilities2026-08-19