CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2026-74981

    Last Modified: 25 Aug 2026

    Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-74980

    Last Modified: 25 Aug 2026

    Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-74982

    Last Modified: 25 Aug 2026

    Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    6.8
    Medium

    CVE-2026-74984

    Last Modified: 25 Aug 2026

    Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74979

    Last Modified: 20 Aug 2026

    Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74975

    Last Modified: 25 Aug 2026

    Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-74977

    Last Modified: 25 Aug 2026

    Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-74978

    Last Modified: 25 Aug 2026

    Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74968

    Last Modified: 20 Aug 2026

    Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.1
    Critical

    CVE-2026-74961

    Last Modified: 20 Aug 2026

    Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-74966

    Last Modified: 25 Aug 2026

    Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74970

    Last Modified: 25 Aug 2026

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-74958

    Last Modified: 19 Aug 2026

    Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.1
    Critical

    CVE-2026-74956

    Last Modified: 19 Aug 2026

    Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74955

    Last Modified: 19 Aug 2026

    Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-74954

    Last Modified: 19 Aug 2026

    Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-74951

    Last Modified: 19 Aug 2026

    Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74950

    Last Modified: 19 Aug 2026

    Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74947

    Last Modified: 19 Aug 2026

    Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74952

    Last Modified: 1 Sept 2026

    Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2.

    Published: 18 Aug 2026
    9.1
    Critical

    CVE-2026-74938

    Last Modified: 19 Aug 2026

    Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74937

    Last Modified: 19 Aug 2026

    Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

    Published: 18 Aug 2026
    10
    Critical

    CVE-2026-75874

    Last Modified: 1 Sept 2026

    Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74990

    Last Modified: 1 Sept 2026

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74987

    Last Modified: 1 Sept 2026

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-74976

    Last Modified: 19 Aug 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-74983

    Last Modified: 21 Aug 2026

    Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74974

    Last Modified: 19 Aug 2026

    Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    4.3
    Medium

    CVE-2026-74972

    Last Modified: 19 Aug 2026

    Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    4.3
    Medium

    CVE-2026-74971

    Last Modified: 19 Aug 2026

    Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    4.2
    Medium

    CVE-2026-74973

    Last Modified: 19 Aug 2026

    Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74969

    Last Modified: 19 Aug 2026

    Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74967

    Last Modified: 21 Aug 2026

    Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74963

    Last Modified: 19 Aug 2026

    Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74964

    Last Modified: 19 Aug 2026

    Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74965

    Last Modified: 19 Aug 2026

    Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.1
    Critical

    CVE-2026-74959

    Last Modified: 24 Aug 2026

    Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-74962

    Last Modified: 21 Aug 2026

    Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-74957

    Last Modified: 24 Aug 2026

    Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-74960

    Last Modified: 24 Aug 2026

    Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74949

    Last Modified: 1 Sept 2026

    Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74953

    Last Modified: 19 Aug 2026

    Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74946

    Last Modified: 19 Aug 2026

    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-74948

    Last Modified: 24 Aug 2026

    Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74944

    Last Modified: 21 Aug 2026

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74942

    Last Modified: 19 Aug 2026

    Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-74945

    Last Modified: 24 Aug 2026

    Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74943

    Last Modified: 21 Aug 2026

    Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74939

    Last Modified: 19 Aug 2026

    Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-74940

    Last Modified: 21 Aug 2026

    Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

    Published: 18 Aug 2026