rootpwn

Vulnerabilities

Mozilla Products Hit by 20+ Critical Vulnerabilities

The French CERT released an alert on September 16, 2026, detailing a suite of 22 CVEs affecting older releases of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The flaws enable attackers to elevate privileges, launch remote denial‑of‑service attacks, and exfiltrate sensitive data. Patches are available through Mozilla’s MFSA 2026‑90 to 2026‑95 advisories. All affected users should update immediately.

RootPwn’s latest bulletin comes from the French Computer Emergency Response Team (CERT‑FR), which identified a wave of critical bugs across Mozilla’s flagship browsers and email client. The vulnerabilities, numbered CVE‑2026‑92005 through CVE‑2026‑92026, expose users to privilege escalation, remote denial‑of‑service, and data confidentiality breaches.

What’s at stake?

  • Privilege escalation – attackers can gain higher OS permissions.
  • Remote DoS – a single exploit can crash the application from afar.
  • Data leakage – sensitive information may be read or transmitted.

Affected Software

  • Firefox ESR versions <115.41, <140.16, <153.3, and <156.
  • Firefox versions <156.
  • Thunderbird ESR versions <140.16 and <156.
  • Thunderbird versions <156.

Patch status

  • Mozilla Security Advisories MFSA 2026‑90 through MFSA 2026‑95 contain the fixes.
  • All patches are bundled in the next release of each product line.
"Users running any of the listed versions should update immediately to eliminate the risk," the alert states.

For a full list of CVEs and detailed technical notes, consult the Mozilla Security Advisories and the CVE database. Stay patched, stay safe.

Mozilla Firefox Thunderbird CVE Privilege Escalation Denial of Service Data Breach

← All news