Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-2795 — Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

firefox thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-2794 — Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Andro…

Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability affects Firefox < 148.

firefox | Remote | Information Disclosure
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2793 — Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8,…

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume tha…

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-2792 — Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thu…

Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-2791 — Mitigation bypass in the Networking: Cache component

Mitigation bypass in the Networking: Cache component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2790 — Same-origin policy bypass in the Networking: JAR component

Same-origin policy bypass in the Networking: JAR component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Misconfiguration
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2789 — Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2788 — Incorrect boundary conditions in the Audio/Video: GMP component

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2787 — Use-after-free in the DOM: Window and Location component

Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2786 — Use-after-free in the JavaScript Engine component

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2785 — Invalid pointer in the JavaScript Engine component

Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2784 — Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Misconfiguration
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
7.5 HIGH
CVE-2026-2783 — Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Information Disclosure
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2782 — Privilege escalation in the Netmonitor component

Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Authorization
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-2781 — Integer overflow in the Libraries component in NSS

Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2780 — Privilege escalation in the Netmonitor component

Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-2779 — Incorrect boundary conditions in the Networking: JAR component

Incorrect boundary conditions in the Networking: JAR component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Memory Corruption
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
10.0 CRITICAL
CVE-2026-2778 — Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component

Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thun…

firefox firefox_esr thunderbird | Remote | Misconfiguration
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
9.8 CRITICAL
CVE-2026-2777 — Privilege escalation in the Messaging System component

Privilege escalation in the Messaging System component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

firefox firefox_esr thunderbird | Remote | Authorization
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
10.0 CRITICAL
CVE-2026-2776 — Sandbox escape due to incorrect boundary conditions in the Telemetry component in Externa…

Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird <…

firefox firefox_esr thunderbird | Remote | Information Disclosure
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
Showing 20 of 5272 Results