Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
- •Firefox versions prior to 152.0.4
- •Thunderbird versions prior to 152.0.1
- •Thunderbird versions prior to 140.12.1
Executive Summary
MS-ISAC Advisory 2026-065 (issued 7/1/2026): multiple vulnerabilities in Mozilla products (Firefox, Thunderbird), the most severe of which could allow for arbitrary code execution. Includes a denial-of-service via malicious LDAP address-book server (CVE-2026-57962), chat UI manipulation by injection (CVE-2026-57963), and memory safety bugs fixed in Firefox 152.0.4 (CVE-2026-14241). There are currently no reports of these vulnerabilities being exploited in the wild.
Municipal Impact
MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal agencies should update Firefox and Thunderbird promptly.
SMB Impact
MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.
Recommended Actions
- Apply appropriate updates provided by Mozilla to vulnerable systems immediately after appropriate testing.
- Ensure use of only fully supported browsers and email clients.
- Apply the principle of least privilege to all systems and services.
Grey Matter Analysis
References
- https://learn.cisecurity.org/e/799323/curity-advisories-mfsa2026-62-/4vzk1f/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/curity-advisories-mfsa2026-63-/4vzk1j/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/curity-advisories-mfsa2026-64-/4vzk1m/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/en-US-security-advisories-/4vzk1b/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-14241/4vzk11/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-57962/4vzk14/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/vename-cgi-name-CVE-2026-57963/4vzk17/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
- https://learn.cisecurity.org/e/799323/resources--type-advisory/4vzjz1/2720687364/h/GqrOJp84X2Dsf8Fr58ZShQvjl7Wujf0fHCdOJoBM1_0
Tags
Related Intelligence
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter