[UPDATE] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird to execute arbitrary code, gain elevated privileges, cause memory corruption, bypass security measures, escape the sandbox, disclose confidential information, manipulate data, and trigger denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to execute arbitrary code and gain elevated privileges.
- Who is affected
- Deployments of Mozilla Firefox, Firefox ESR, and Thunderbird.
- Urgency
- Remediation is high urgency due to the potential for exploitation.
- Action
- Update to the latest version of Mozilla Firefox, Firefox ESR, and Thunderbird.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firefox, Firefox ESR and Thunderbird
Get an email when a new Firefox, Firefox ESR and Thunderbird advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1959
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-122890.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122900.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122910.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122920.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122930.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122940.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122950.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122960.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122970.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-122980.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
Recent advisories for Mozilla Firefox
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund · 2026-08-25
- high[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilitiescert-bund · 2026-08-18
- medium[NEW] [medium] Mozilla Firefox: Multiple vulnerabilities allow unspecified attackcert-bund · 2026-08-17
- medium[NEW] [medium] Mozilla Firefox for Android: Vulnerability Enables Information Disclosurecert-bund · 2026-08-05
- unknownMozilla Firefox Information Disclosure Vulnerabilityhkcert · 2026-08-05
- unknownVulnerability in Mozilla Firefox for Android (August 5, 2026)cert-fr-avis · 2026-08-05
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25