Mozilla Firefox: 25 Coordinated Vulnerability Disclosures Impacting Multiple Components
Mozilla disclosed 25 vulnerabilities in Firefox, Firefox ESR, and Thunderbird on September 15, 2026, impacting components from networking to security.

Key findings
- Mozilla disclosed 25 vulnerabilities in Firefox, Firefox ESR, and Thunderbird on September 15, 2026.
- Vulnerabilities include privilege escalation, sandbox escapes, mitigation bypasses, and denial-of-service flaws.
- High-severity privilege escalation bugs (CVSSv3 8.8) affect Enterprise Policies, Session Restore, and DevTools.
- All issues were fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Users are urged to update to the latest versions to mitigate these risks.
On September 15, 2026, Mozilla Corporation disclosed a batch of 25 vulnerabilities affecting its Firefox browser, along with Firefox ESR and Thunderbird. The vulnerabilities were all disclosed on the same day, indicating a coordinated release of security fixes. These issues span various components of the browser, including networking, widgets, security, and graphics, with several leading to critical impacts such as privilege escalation and sandbox escapes.
Several vulnerabilities fall into the category of mitigation bypasses, affecting components like Widget: Win32, Networking, and the Popup Blocker. Specifically, CVE-2026-92079, CVE-2026-92075, and CVE-2026-92074 represent these types of flaws, potentially allowing attackers to circumvent security measures.
Denial-of-service (DoS) vulnerabilities were also present, impacting the Security component (CVE-2026-92078) and the SVG component (CVE-2026-92077). Additionally, incorrect boundary conditions were identified in the Networking (CVE-2026-92076), Safe Browsing (CVE-2026-92072), and Security: Process Sandboxing (CVE-2026-92061) components, as well as in the DOM: Editor (CVE-2026-92059).
A significant concern is the presence of privilege escalation vulnerabilities, including CVE-2026-92073 in Enterprise Policies, CVE-2026-92062 in Session Restore, and CVE-2026-92055 in DevTools. These high-severity flaws (CVSSv3 8.8) could allow attackers to gain elevated permissions on a user's system. Sandbox escape vulnerabilities were also noted, particularly in the Widget: Win32 component (CVE-2026-92065, CVE-2026-92064, CVE-2026-92071) and the Profile Backup component (CVE-2026-92066).
Other vulnerabilities include information disclosure in the Networking component (CVE-2026-92070), spoofing in DOM: Navigation (CVE-2026-92069), site isolation issues in Reader Mode (CVE-2026-92068), use-after-free bugs in Widget: Gtk (CVE-2026-92067), Internationalization (CVE-2026-92060), and Graphics (CVE-2026-92058, CVE-2026-92056), and a DoS in Audio/Video (CVE-2026-92063).
All 25 vulnerabilities were addressed in Firefox version 156, Firefox ESR version 153.3, and Thunderbird version 156, with some exceptions noted for specific CVEs impacting Thunderbird only or Firefox/Thunderbird but not ESR. Users are strongly advised to update to the patched versions to protect themselves from these newly disclosed security risks. The coordinated disclosure of such a large number of vulnerabilities underscores the importance of timely patching for maintaining browser security. The breadth of affected components highlights the complex security surface of modern web browsers.