Firefox
This hub aggregates every CVE we track for Firefox, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Consumer Softwaredesktop app
3,280
CVEs tracked
917
Critical
984
High
15
In CISA KEV
Severity distribution
MEDIUM1,307HIGH984CRITICAL917LOW72
Monthly trend
18
12
27
20
0
14
12
18
22
13
15
17
19
14
16
16
16
18
54
48
51
43
47
66
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Firefox.
- CVE-2026-16361Memory safety bugs fixed in Thunderbird ESR 140.139.8
- CVE-2026-16360Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16412Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16411Memory safety bugs fixed in Firefox 1539.8
- CVE-2026-16410JIT miscompilation in the JavaScript Engine: JIT component9.8
- CVE-2026-16409Invalid pointer in the Security: PSM component7.5
- CVE-2026-16408Integer overflow in the Audio/Video: Playback component9.8
- CVE-2026-16407Mitigation bypass in the DOM: Service Workers component9.8
- CVE-2026-16406Mitigation bypass in the Networking component9.1
- CVE-2026-16405Information disclosure in the Networking: WebSockets component7.5
- CVE-2026-16404Spoofing issue in Firefox for Android7.4
- CVE-2026-16403Spoofing issue in the Address Bar component6.5
- CVE-2026-16402Integer overflow in the Graphics: ImageLib component9.8
- CVE-2026-16401Privilege escalation in the Data Loss Prevention component8.8
- CVE-2026-16400Information disclosure in the DOM: Security component7.5
Product normalization is registry-driven with AI assist and human review. How it works