Multiple vulnerabilities in Mozilla products (August 19, 2026)
Multiple vulnerabilities have been discovered in Mozilla products. Some of them allow an attacker to cause privilege escalation, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Mozilla products allow privilege escalation, remote denial of service, and data confidentiality breaches.
- Who is affected
- All users of Mozilla Firefox and other Mozilla products are potentially affected.
- Urgency
- Urgent updates needed due to privilege escalation and data breach capabilities.
- Action
- Update Firefox and other Mozilla products to the latest patched versions immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1054/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-749730.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749660.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749440.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749360.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749890.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749480.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749630.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749750.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749460.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749470.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
Referenced CVEs
+10 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund
- unknownMozilla Products Multiple Vulnerabilitieshkcert
- unknownDSA-6451-1 firefox-esr - security updatedebian
- criticalCVE-2026-75874: Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefo…nvd
- criticalCVE-2026-74990: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird…nvd
- unknownCVE-2026-74989: Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory…nvd
- unknownCVE-2026-74988: Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs…nvd
- criticalCVE-2026-74987: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird…nvd
- unknownCVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixe…nvd
- unknownCVE-2026-74985: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Fir…nvd
- unknownCVE-2026-74984: Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154…nvd
- highCVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firef…nvd
Recent advisories for Mozilla products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMozilla Products Multiple Vulnerabilitieshkcert · 2026-08-19
- unknownMozilla Products Multiple Vulnerabilitieshkcert · 2026-07-22
- unknownMultiple vulnerabilities in Mozilla products (July 22, 2026)cert-fr-avis · 2026-07-22
- unknownMozilla Products Multiple Vulnerabilitieshkcert · 2026-07-15
- unknownMozilla Products Multiple Vulnerabilitieshkcert · 2026-07-02
- criticalexploitedCVE-2010-3765: Mozilla Multiple Products Remote Code Execution Vulnerabilitycisa-kev · 2025-10-06
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Oracle Virtualization (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Axis products (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)2026-08-19