Firefox
This hub aggregates every CVE we track for Firefox, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
3,282
CVEs tracked
918
Critical
984
High
15
In CISA KEV
Severity distribution
MEDIUM1,308HIGH984CRITICAL918LOW72
Monthly trend
12
27
20
0
14
12
18
22
13
15
17
19
14
16
16
16
18
54
48
51
43
47
67
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Firefox.
- CVE-2026-18809Information disclosure in Firefox for Android and Firefox Focus for Android6.5
- CVE-2026-16361Memory safety bugs fixed in Thunderbird ESR 140.139.8
- CVE-2026-16360Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16412Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16411Memory safety bugs fixed in Firefox 1539.8
- CVE-2026-16410JIT miscompilation in the JavaScript Engine: JIT component9.8
- CVE-2026-16409Invalid pointer in the Security: PSM component7.5
- CVE-2026-16408Integer overflow in the Audio/Video: Playback component9.8
- CVE-2026-16407Mitigation bypass in the DOM: Service Workers component9.8
- CVE-2026-16406Mitigation bypass in the Networking component9.1
- CVE-2026-16405Information disclosure in the Networking: WebSockets component7.5
- CVE-2026-16404Spoofing issue in Firefox for Android7.4
- CVE-2026-16403Spoofing issue in the Address Bar component6.5
- CVE-2026-16402Integer overflow in the Graphics: ImageLib component9.8
- CVE-2026-16401Privilege escalation in the Data Loss Prevention component8.8
Product normalization is registry-driven with AI assist and human review. How it works