Mozilla Products Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities affect Mozilla products including Firefox and derivatives.
- Who is affected
- Users of Mozilla Firefox and related products are affected.
- Urgency
- Multiple CVEs present; assess severity via CVE details before deploying patches.
- Action
- Update Mozilla products to the latest patched versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Mozilla Products
Get an email when a new Mozilla Products advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/mozilla-products-multiple-vulnerabilities_20260902
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-163650.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-163710.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749520.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-758740.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-812670.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Mozilla Firefox and Thunderbird: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilitiescert-bund
- unknownDSA-6481-1 firefox-esr - security updatedebian
- unknownMultiple vulnerabilities in Mozilla products (02 September 2026)cert-fr-avis
- highCVE-2026-84642: The values of the mail.allowed_attachment_hostnames advanced config setting were used in a reg…nvd
- highCVE-2026-84641: A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a cra…nvd
- highCVE-2026-84640: A maliciously constructed mail header could lead to a one byte read past the end of a buffer. …nvd
- criticalCVE-2026-84639: Triggering an error condition in certain MIME bodies would cause uninitialized memory to be us…nvd
- criticalCVE-2026-84637: Malicious calendar invitations could use file URI attachments to launch local or network-hoste…nvd
- highCVE-2026-84145: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 14…nvd
- unknownCVE-2026-84144: Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs…nvd
More from HKCERT Security Bulletins
- unknownGitHub Enterprise Server Multiple Vulnerabilities2026-09-03
- unknownCisco Products Multiple Vulnerabilities2026-09-03
- unknownJenkins Multiple Vulnerabilities2026-09-03
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-02
- unknownF5 Products Multiple Vulnerabilities2026-09-02