[UPDATE] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird to execute arbitrary code, gain elevated privileges, cause memory corruption, bypass security measures, escape the sandbox, disclose confidential information, manipulate data, and trigger denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to execute arbitrary code and gain elevated privileges.
- Who is affected
- Deployments of Mozilla Firefox, Firefox ESR, and Thunderbird.
- Urgency
- Remediation is high urgency due to the potential for exploitation.
- Action
- Update to the latest version of Mozilla Firefox, Firefox ESR, and Thunderbird.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firefox, Firefox ESR and Thunderbird
Get an email when a new Firefox, Firefox ESR and Thunderbird advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1959
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-122890.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122900.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122910.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122920.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122930.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122940.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122950.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122960.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122970.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122980.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
Recent advisories for Mozilla Firefox
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Mozilla Firefox and Thunderbird: Multiple Vulnerabilitiescert-bund · 2026-09-04
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund · 2026-09-04
- high[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilitiescert-bund · 2026-09-04
- unknownVulnerability in Mozilla Firefox for iOS (September 01, 2026)cert-fr-avis · 2026-09-01
- medium[NEW] [medium] Mozilla Firefox: Multiple vulnerabilities allow unspecified attackcert-bund · 2026-08-17
- medium[NEW] [medium] Mozilla Firefox for Android: Vulnerability Enables Information Disclosurecert-bund · 2026-08-05
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Langflow: Multiple vulnerabilities2026-09-04
- medium[NEW] [medium] Grafana Enterprise: Multiple vulnerabilities allow gaining user or administrator privileges2026-09-04
- low[NEW] [low] Checkmk: Vulnerability allows Denial of Service2026-09-04
- low[NEW] [low] ImageMagick: Multiple vulnerabilities allow Denial of Service2026-09-04
- critical[NEW] [critical] vm2: Multiple vulnerabilities allow code execution2026-09-04