Mozilla Product Security Update Advisory

Mozilla Product Security Update Advisory

Mozilla Product Security Update Advisory


Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The affected vulnerabilities are CVE-2026-16361, CVE-2026-16411, and CVE-2026-16412.

Vulnerability Details

  • CVE-2026-16361 is a memory safety vulnerability affecting Firefox ESR and Thunderbird ESR.
  • CVE-2026-16411 is a memory safety vulnerability affecting Firefox and Thunderbird.
  • CVE-2026-16412 is a memory safety vulnerability affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR.

Affected Products and Fixed Versions

  • CVE-2026-16361.
    • Firefox ESR 115.37.
    • Firefox ESR 140.12.
    • Thunderbird ESR 140.12.
    • The patched versions are Firefox ESR 115.38, Firefox ESR 140.13, And Thunderbird ESR 140.13.
  • CVE-2026-16411.
    • Firefox 152.
    • Thunderbird 152.
    • The patched versions are Firefox 153 and Thunderbird 153.
  • CVE-2026-16412.
    • Firefox ESR 140.12.
    • Firefox 152.
    • Thunderbird ESR 140.12.
    • Thunderbird 152.
    • The patched versions are Firefox ESR 140.13, Firefox 153, Thunderbird ESR 140.13, And Thunderbird 153.

Recommendations

You should apply the latest updates to upgrade to the versions that include the Vulnerability Patch.