Firefox
This hub aggregates every CVE we track for Firefox, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
3,359
CVEs tracked
944
Critical
1,018
High
15
In CISA KEV
Severity distribution
MEDIUM1,326HIGH1,018CRITICAL944LOW71
Monthly trend
27
20
0
14
12
18
22
13
15
17
19
14
16
16
16
18
54
48
51
43
47
67
59
29
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Firefox.
- CVE-2026-84144Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.27.5
- CVE-2026-84143Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.159.8
- CVE-2026-84142Internally found bugs fixed in Thunderbird 1559.8
- CVE-2026-84141Integer overflow in the Graphics: ImageLib component9.8
- CVE-2026-84140Site isolation issue in the DOM: Navigation component9.8
- CVE-2026-84139Clickjacking issue in the DOM: Events component6.1
- CVE-2026-84138Denial-of-service in the PDF Viewer component6.5
- CVE-2026-84137Spoofing issue in the DOM: Core & HTML component4.3
- CVE-2026-84136Other issue in the DOM: Navigation component6.1
- CVE-2026-84135Other issue in Firefox Focus for Android9.8
- CVE-2026-84134Other issue in the Profile Backup component9.8
- CVE-2026-84133Site isolation issue in the DOM: Push Subscriptions component9.8
- CVE-2026-84132Information disclosure in the Networking: HTTP component7.5
- CVE-2026-84130Information disclosure in the Graphics: WebGPU component7.5
- CVE-2026-84129Site isolation issue in the DOM: Navigation component9.8
Product normalization is registry-driven with AI assist and human review. How it works