Skip to content

Multiple vulnerabilities in Mozilla Firefox

Threats.Kaspersky • September 30, 2026

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

Denial of service vulnerability in the Audio/Video: Playback component can be exploited remotely to cause denial of service.

A remote code execution vulnerability in the Widget component can be exploited remotely to execute arbitrary code.

Security vulnerability in the DOM: component can be exploited to bypass security restrictions.

Denial of service vulnerability in the Storage: Quota Manager component can be exploited remotely to cause denial of service.

Security vulnerability in the Security: Process Sandboxing component can be exploited to bypass security restrictions.

A remote code execution vulnerability in the Graphics: WebGPU component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the DOM: Content Processes component can be exploited remotely to execute arbitrary code.

Denial of service vulnerability in the Graphics: WebGPU component can be exploited remotely to cause denial of service.

A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.

Information disclosure vulnerability in the Networking: JAR component can be exploited to obtain sensitive information.

A remote code execution vulnerability in the Networking: Cache component can be exploited remotely to execute arbitrary code.

Security vulnerability can be exploited to bypass security restrictions.

A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the Storage: IndexedDB component can be exploited remotely to execute arbitrary code.

Security vulnerability in the Graphics component can be exploited to bypass security restrictions.

A remote code execution vulnerability in the Graphics: Canvas2D component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the XSLT component can be exploited remotely to execute arbitrary code.

Denial of service vulnerability in the Graphics: WebRender component can be exploited remotely to cause denial of service.

Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.

Denial of service vulnerability in the Audio/Video component can be exploited remotely to cause denial of service.

A remote code execution vulnerability in the Layout: Text and Fonts component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the Graphics component can be exploited remotely to execute arbitrary code.

Security vulnerability in the XUL component can be exploited to bypass security restrictions.

Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.

Denial of service vulnerability in the Internationalization component can be exploited remotely to cause denial of service.

Information disclosure vulnerability in the Networking component can be exploited to obtain sensitive information.

Denial of service vulnerability in the Networking component can be exploited remotely to cause denial of service.

A remote code execution vulnerability in the Graphics: WebRender component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.

Security vulnerability in the DLL Services component can be exploited to bypass security restrictions.

Security vulnerability in the WebExtensions component can be exploited to bypass security restrictions.

A remote code execution vulnerability in the Preferences: Backend component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the Audio/Video component can be exploited remotely to execute arbitrary code.

Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.

Security vulnerability in the DevTools component can be exploited to bypass security restrictions.

Denial of service vulnerability in the DevTools component can be exploited remotely to cause denial of service.

Denial of service vulnerability in the JavaScript Engine: JIT component can be exploited remotely to cause denial of service.

A remote code execution vulnerability in the CSS Parsing and Computation component can be exploited remotely to execute arbitrary code.

A remote code execution vulnerability in the Widget: Gtk component can be exploited remotely to execute arbitrary code.

Denial of service vulnerability in the XPCOM component can be exploited remotely to cause denial of service.

Security vulnerability in the Address Bar component can be exploited to bypass security restrictions.

Security UI vulnerability in the Networking: HTTP component can be exploited to spoof user interface.

Security UI vulnerability in the Downloads component in Firefox for Android can be exploited to spoof user interface.

Security vulnerability in the Places component can be exploited to bypass security restrictions.

A remote code execution vulnerability in the JavaScript Engine: JIT component can be exploited remotely to execute arbitrary code.

Denial of service vulnerability in the Storage: StorageManager component can be exploited remotely to cause denial of service.

Security vulnerability in the Bookmarks & History component can be exploited to bypass security restrictions.

Security vulnerability in the DOM: Security component can be exploited to bypass security restrictions.

A remote code execution vulnerability in the DOM: UI Events & Focus Handling component can be exploited remotely to execute arbitrary code.

CVE-2026-100756 unknown

CVE-2026-100757 critical

CVE-2026-100758 unknown

CVE-2026-100759 unknown

CVE-2026-100760 unknown

CVE-2026-100761 critical

CVE-2026-100762 critical

CVE-2026-100763 unknown

CVE-2026-100764 critical

CVE-2026-100765 critical

CVE-2026-100766 warning

CVE-2026-100767 critical

CVE-2026-100768 critical

CVE-2026-100769 critical

CVE-2026-100770 critical

CVE-2026-100771 unknown

CVE-2026-100772 critical

CVE-2026-100773 critical

CVE-2026-100774 critical

CVE-2026-100775 unknown

CVE-2026-100776 critical

CVE-2026-100777 critical

CVE-2026-100778 critical

CVE-2026-100779 critical

CVE-2026-100780 critical

CVE-2026-100781 unknown

CVE-2026-100782 critical

CVE-2026-100783 warning

CVE-2026-100784 critical

CVE-2026-100785 critical

CVE-2026-100786 critical

CVE-2026-100787 unknown

CVE-2026-100788 unknown

CVE-2026-100789 critical

CVE-2026-100790 critical

CVE-2026-100791 critical

CVE-2026-100792 unknown

CVE-2026-100793 unknown

CVE-2026-100794 unknown

CVE-2026-100796 critical

CVE-2026-100797 critical

CVE-2026-100798 unknown

CVE-2026-100799 warning

CVE-2026-100800 critical

CVE-2026-100801 critical

CVE-2026-100802 warning

CVE-2026-100803 unknown

CVE-2026-100804 critical

CVE-2026-100805 critical

CVE-2026-100806 warning

CVE-2026-100807 critical

CVE-2026-100808 unknown

CVE-2026-100809 unknown

CVE-2026-100810 unknown

CVE-2026-100811 critical

CVE-2026-100813 critical

CVE-2026-100814 critical

CVE-2026-100815 critical

CVE-2026-100816 unknown

CVE-2026-100817 unknown

CVE-2026-100818 critical

CVE-2026-100819 critical

CVE-2026-100820 critical

CVE-2026-100821 unknown

CVE-2026-100822 unknown

CVE-2026-100823 unknown

CVE-2026-100824 critical

CVE-2026-100825 critical

CVE-2026-100828 unknown

CVE-2026-100829 unknown

CVE-2026-100830 unknown

CVE-2026-100831 critical

CVE-2026-96869 warning

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com