T
Threats
Mozilla Firefox and Thunderbird Security Vulnerabilities
Overview
CVE: CVE-2026-75874, CVE-2026-74938, CVE-2026-74956, CVE-2026-74979, CVE-2026-74990
Vendor severity: High overall. Mozilla rates CVE-2026-75874, CVE-2026-74938 and CVE-2026-74990 as high impact, CVE-2026-74956 as moderate impact, and CVE-2026-74979 as low impact.
Published: 18 August 2026
Products: Mozilla Firefox, Firefox ESR, Thunderbird and Thunderbird ESR
Affected Versions
CVE-2026-75874
Firefox
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Firefox 154
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-74 - Firefox 154
Thunderbird
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Thunderbird 154
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-78 - Thunderbird 154
CVE-2026-74938
Firefox
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Firefox 154 and Firefox ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-74 - Firefox 154, Mozilla Foundation Security Advisory 2026-77 - Firefox ESR 153.1
Thunderbird
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Thunderbird 154 and Thunderbird ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-78 - Thunderbird 154, Mozilla Foundation Security Advisory 2026-80 - Thunderbird ESR 153.1
CVE-2026-74956
Firefox
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Firefox 154 and Firefox ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-74 - Firefox 154, Mozilla Foundation Security Advisory 2026-77 - Firefox ESR 153.1
Thunderbird
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Thunderbird 154 and Thunderbird ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-78 - Thunderbird 154, Mozilla Foundation Security Advisory 2026-80 - Thunderbird ESR 153.1
CVE-2026-74979
Firefox
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Firefox 154 and Firefox ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-74 - Firefox 154, Mozilla Foundation Security Advisory 2026-77 - Firefox ESR 153.1
Thunderbird
Affected: The vendor has not specified an exact affected-version range as of 18 August 2026.
Fixed: Thunderbird 154 and Thunderbird ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-78 - Thunderbird 154, Mozilla Foundation Security Advisory 2026-80 - Thunderbird ESR 153.1
CVE-2026-74990
Firefox
Affected: Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13 and Firefox ESR 153.0
Fixed: Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14 and Firefox ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-74 - Firefox 154, Mozilla Foundation Security Advisory 2026-75 - Firefox ESR 115.39, Mozilla Foundation Security Advisory 2026-76 - Firefox ESR 140.14, Mozilla Foundation Security Advisory 2026-77 - Firefox ESR 153.1
Thunderbird
Affected: Thunderbird 153, Thunderbird ESR 140.13 and Thunderbird ESR 153.0
Fixed: Thunderbird 154, Thunderbird ESR 140.14 and Thunderbird ESR 153.1
Not affected: Not specified by Mozilla.
Source: Mozilla Foundation Security Advisory 2026-78 - Thunderbird 154, Mozilla Foundation Security Advisory 2026-79 - Thunderbird ESR 140.14, Mozilla Foundation Security Advisory 2026-80 - Thunderbird ESR 153.1
Vulnerability Breakdown
CVE-2026-75874 - Remote Settings Client sandbox escape
Severity: High, according to Mozilla
CVSS: Mozilla has not published a CVSS score in the reviewed advisories.
Description: A sandbox escape affects the Remote Settings Client component.
Impact: The flaw can allow code or activity to escape the affected sandbox boundary.
Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.
CVE-2026-74938 - JavaScript garbage collector mitigation bypass
Severity: High, according to Mozilla
CVSS: Mozilla has not published a CVSS score in the reviewed advisories.
Description: A mitigation bypass affects the JavaScript garbage collector component.
Impact: The flaw can bypass a security mitigation in the affected component.
Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.
CVE-2026-74990 - Memory-safety and other security defects
Severity: High, according to Mozilla
CVSS: Mozilla has not published a CVSS score in the reviewed advisories.
Description: Mozilla identified internally found bugs showing evidence of memory corruption or other security-relevant defects. Mozilla states that some could have been exploitable with enough effort.
Impact: Successful exploitation of some defects could affect the confidentiality, integrity or availability of the application and its data.
Conditions: Mozilla has not published specific exploitation prerequisites in the reviewed advisories.
CVE-2026-74956 - Service Worker same-origin policy bypass
Severity: Moderate, according to Mozilla
CVSS: Mozilla has not published a CVSS score in the reviewed advisories.
Description: A same-origin policy bypass affects the DOM Service Workers component.
Impact: The flaw can weaken browser origin-separation protections.
Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.
CVE-2026-74979 - Add-ons Manager mitigation bypass
Severity: Low, according to Mozilla
CVSS: Mozilla has not published a CVSS score in the reviewed advisories.
Description: A mitigation bypass affects the Add-ons Manager component.
Impact: The flaw can bypass a security mitigation in the affected component.
Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.
Mitigation
Update Firefox to version 154.
Update supported Firefox ESR branches to 115.39, 140.14 or 153.1, as applicable.
Update Thunderbird to version 154.
Update supported Thunderbird ESR branches to 140.14 or 153.1, as applicable.
Prioritise internet-facing and widely deployed browser installations.
Confirm updated versions through software inventory and endpoint management tools.
Restart applications where required to complete installation.
Summary for IT Teams
Products: Mozilla Firefox, Firefox ESR, Thunderbird and Thunderbird ESR
Threat Level: High overall, based on Mozilla's vendor impact rating
Action Required: Deploy the fixed releases, verify successful installation and investigate any systems that cannot be updated promptly.
Reference
Mozilla Foundation Security Advisory 2026-75 - Firefox ESR 115.39
Mozilla Foundation Security Advisory 2026-76 - Firefox ESR 140.14
Mozilla Foundation Security Advisory 2026-77 - Firefox ESR 153.1
Mozilla Foundation Security Advisory 2026-78 - Thunderbird 154
Mozilla Foundation Security Advisory 2026-79 - Thunderbird ESR 140.14
Mozilla Foundation Security Advisory 2026-80 - Thunderbird ESR 153.1
Need Help?
Please get in touch on 1300 769 460 or email the Secure ISS team. We are here to help your organisation assess exposure, deploy updates and strengthen its cybersecurity posture.

