T

Threats

Mozilla Firefox and Thunderbird Security Vulnerabilities

Overview

  • CVE: CVE-2026-75874, CVE-2026-74938, CVE-2026-74956, CVE-2026-74979, CVE-2026-74990

  • Vendor severity: High overall. Mozilla rates CVE-2026-75874, CVE-2026-74938 and CVE-2026-74990 as high impact, CVE-2026-74956 as moderate impact, and CVE-2026-74979 as low impact.

  • Published: 18 August 2026

  • Products: Mozilla Firefox, Firefox ESR, Thunderbird and Thunderbird ESR


Affected Versions

CVE-2026-75874

Firefox

Thunderbird

CVE-2026-74938

Firefox

Thunderbird

CVE-2026-74956

Firefox

Thunderbird

CVE-2026-74979

Firefox

Thunderbird

CVE-2026-74990

Firefox

Thunderbird


Vulnerability Breakdown

CVE-2026-75874 - Remote Settings Client sandbox escape

  • Severity: High, according to Mozilla

  • CVSS: Mozilla has not published a CVSS score in the reviewed advisories.

  • Description: A sandbox escape affects the Remote Settings Client component.

  • Impact: The flaw can allow code or activity to escape the affected sandbox boundary.

  • Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.

CVE-2026-74938 - JavaScript garbage collector mitigation bypass

  • Severity: High, according to Mozilla

  • CVSS: Mozilla has not published a CVSS score in the reviewed advisories.

  • Description: A mitigation bypass affects the JavaScript garbage collector component.

  • Impact: The flaw can bypass a security mitigation in the affected component.

  • Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.

CVE-2026-74990 - Memory-safety and other security defects

  • Severity: High, according to Mozilla

  • CVSS: Mozilla has not published a CVSS score in the reviewed advisories.

  • Description: Mozilla identified internally found bugs showing evidence of memory corruption or other security-relevant defects. Mozilla states that some could have been exploitable with enough effort.

  • Impact: Successful exploitation of some defects could affect the confidentiality, integrity or availability of the application and its data.

  • Conditions: Mozilla has not published specific exploitation prerequisites in the reviewed advisories.

CVE-2026-74956 - Service Worker same-origin policy bypass

  • Severity: Moderate, according to Mozilla

  • CVSS: Mozilla has not published a CVSS score in the reviewed advisories.

  • Description: A same-origin policy bypass affects the DOM Service Workers component.

  • Impact: The flaw can weaken browser origin-separation protections.

  • Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.

CVE-2026-74979 - Add-ons Manager mitigation bypass

  • Severity: Low, according to Mozilla

  • CVSS: Mozilla has not published a CVSS score in the reviewed advisories.

  • Description: A mitigation bypass affects the Add-ons Manager component.

  • Impact: The flaw can bypass a security mitigation in the affected component.

  • Conditions: Mozilla has not published exploitation prerequisites in the reviewed advisories.


Mitigation

  • Update Firefox to version 154.

  • Update supported Firefox ESR branches to 115.39, 140.14 or 153.1, as applicable.

  • Update Thunderbird to version 154.

  • Update supported Thunderbird ESR branches to 140.14 or 153.1, as applicable.

  • Prioritise internet-facing and widely deployed browser installations.

  • Confirm updated versions through software inventory and endpoint management tools.

  • Restart applications where required to complete installation.


Summary for IT Teams

  • Products: Mozilla Firefox, Firefox ESR, Thunderbird and Thunderbird ESR

  • Threat Level: High overall, based on Mozilla's vendor impact rating

  • Action Required: Deploy the fixed releases, verify successful installation and investigate any systems that cannot be updated promptly.


Reference


Need Help?

Please get in touch on 1300 769 460 or email the Secure ISS team. We are here to help your organisation assess exposure, deploy updates and strengthen its cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.