Mozilla Firefox ESR: 25 Coordinated Vulnerabilities Disclosed, Including Privilege Escalation and Sandbox Escapes
Mozilla disclosed a coordinated batch of 25 vulnerabilities in Firefox, Firefox ESR, and Thunderbird on September 15, 2026, including privilege escalation and sandbox escape flaws.

Key findings
- Mozilla disclosed 25 vulnerabilities in Firefox, Firefox ESR, and Thunderbird on September 15, 2026.
- The batch includes privilege escalation, sandbox escapes, mitigation bypasses, and denial-of-service flaws.
- Multiple high-severity privilege escalation bugs (CVSSv3 8.8) affect critical components like Enterprise Policies and Session Restore.
- All 25 vulnerabilities were fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Users are urged to update to the latest versions to mitigate these risks.
On September 15, 2026, Mozilla Corporation disclosed a coordinated batch of 25 vulnerabilities affecting Firefox, Firefox ESR, and Thunderbird. This significant release included a range of security flaws, from denial-of-service and mitigation bypasses to critical privilege escalation and sandbox escape vulnerabilities. The timely disclosure of these issues on a single day suggests a concerted effort by Mozilla to address a cluster of security weaknesses simultaneously.
The vulnerabilities span multiple components within the affected software. Several issues relate to incorrect boundary conditions and sandbox escapes within the Widget: Win32 component, as seen in CVE-2026-92071, CVE-2026-92064, and CVE-2026-92065. Additionally, the Networking component was affected by mitigation bypass and information disclosure flaws (CVE-2026-92075, CVE-2026-92070).
A notable group of high-severity vulnerabilities (CVSSv3 8.8) were identified as privilege escalations. These affected critical components such as Enterprise Policies (CVE-2026-92073), Session Restore (CVE-2026-92062), DevTools (CVE-2026-92055), Memory (CVE-2026-92054), and Graphics: CanvasWebGL (CVE-2026-92053, CVE-2026-92052). Other high-impact issues included mitigation bypasses in the Widget: Win32 (CVE-2026-92079) and Popup Blocker (CVE-2026-92074) components.
Denial-of-service vulnerabilities were also present, impacting the Security component (CVE-2026-92078) and the SVG component (CVE-2026-92077). Use-after-free vulnerabilities were found in the Widget: Gtk (CVE-2026-92067), Internationalization (CVE-2026-92060), Graphics (CVE-2026-92058), and Graphics: Text (CVE-2026-92056) components.
The comprehensive nature of this disclosure underscores the importance of prompt patching. All 25 vulnerabilities were addressed in Firefox version 156, Firefox ESR version 153.3, and Thunderbird version 156. Users of Firefox ESR are strongly urged to update to version 153.3 as soon as possible to protect against these widespread security risks.
This coordinated release highlights Mozilla's commitment to maintaining the security posture of its widely used browsers. By addressing these diverse vulnerabilities in a single update, the company aims to provide a robust security baseline for its users. Staying current with these updates is crucial for mitigating potential exploitation of these flaws. The Vypr Intelligence report noted the broad impact across multiple components and emphasized the need for immediate updates.