VENDOR

Mozilla vulnerabilities: CVEs, exploitation and patches

Every Mozilla CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-92034 CRITICAL 9.1
  2. CVE-2026-92038
    Firefox mitigation bypass in Remote Settings Client Mozilla Firefox ·
    CRITICAL 9.1
  3. CVE-2026-92041 CRITICAL 9.1
  4. CVE-2026-92051 CRITICAL 9.1
  5. CVE-2026-92050
    Firefox sandbox escape via XPConnect race condition Mozilla Firefox ·
    CRITICAL 9.1
  6. CVE-2026-92057
    Firefox Enterprise Policies mitigation bypass Mozilla Firefox ·
    CRITICAL 9.1
  7. CVE-2026-92075
    Firefox mitigation bypass in Networking component Mozilla Firefox ·
    CRITICAL 9.1
  8. CVE-2026-92079
    Firefox Widget Win32 mitigation bypass Mozilla Firefox ·
    CRITICAL 9.1
  9. CVE-2026-74936
    Firefox use-after-free in WebAssembly remote code execution Mozilla Firefox ·
    • PoC PUBLIC
    CRITICAL 9.8
  10. CVE-2026-74943
    Firefox use-after-free in ImageLib allows remote code execution Mozilla Firefox ·
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-74940 CRITICAL 9.8
  12. CVE-2026-74944
    Firefox use-after-free in DOM remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  13. CVE-2026-74964 CRITICAL 9.8
  14. CVE-2026-74979 CRITICAL 9.8
  15. CVE-2026-74987
    Firefox memory-corruption remote attack Mozilla Firefox ·
    CRITICAL 9.8
  16. CVE-2026-74990 CRITICAL 9.8
  17. CVE-2026-74988
    Firefox pre-auth remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  18. CVE-2026-74989
    Firefox memory-corruption remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  19. CVE-2026-74985 CRITICAL 9.8
  20. CVE-2026-84129 CRITICAL 9.8
20 CVEs · page 1 of 2