Open Nav
Sign Up

CISA: Mozilla Releases Security Updates for Firefox and Thunderbird to Address Critical Vulnerabilities

Bar Refael

February 25, 2024

Mozilla has issued critical security updates for Firefox, Firefox ESR, and Thunderbird to address several vulnerabilities. These vulnerabilities, if exploited, could allow a cyber threat actor to take control of an affected system, leading to potential data theft, system compromise, or further network infiltration.

Details: 

The vulnerabilities addressed in these updates are varied in nature and include issues such as buffer overflows, use-after-free errors, and cross-site scripting (XSS) vulnerabilities. These vulnerabilities are particularly concerning as they could allow remote attackers to execute arbitrary code on the user’s system or manipulate the affected software in unintended ways.

Affected Products:

  • Firefox (versions prior to 110.0)
  • Firefox ESR (versions prior to 102.12)
  • Thunderbird (versions prior to 102.12)

Mitigation: 

Mozilla has released the following security advisories with details on the vulnerabilities and the necessary updates:

  • MFSA 2024-05 for Firefox: This advisory addresses multiple vulnerabilities in Firefox 110.0. Users are advised to update to Firefox 110.0 or later to mitigate these risks.
  • MFSA 2024-06 for Firefox ESR: This advisory covers several vulnerabilities in Firefox ESR 102.12. Users should update to Firefox ESR 102.12 or later to ensure protection.
  • MFSA 2024-07 for Thunderbird: This advisory details vulnerabilities in Thunderbird 102.12. It is recommended to update to Thunderbird 102.12 or later to address these security issues.

CISA Recommendations: 

The Cybersecurity and Infrastructure Security Agency (CISA) strongly encourages users and administrators to review the Mozilla Security Advisories and apply the necessary updates as soon as possible to prevent potential exploitation by cyber threat actors.

Stay safe and informed,

OP Innovate Research Team.

Resources highlights

Citrix NetScaler Vulnerabilities Expose Sensitive Data and Session Integrity Risks (CVE-2026-3055 & CVE-2026-4368)

Citrix has released security updates addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway that may allow attackers to leak sensitive data or interfere with…

Read more >

cve-2026-3055

Active Exploitation of Microsoft SharePoint RCE (CVE-2026-20963)

A critical Microsoft SharePoint vulnerability, CVE-2026-20963, is now being actively exploited in the wild. The flaw enables remote code execution (RCE) and has been added…

Read more >

cve-2026-20963

CVE-2026-21509: Microsoft Office Zero-Day With Public PoC

CVE-2026-21509 is an actively exploited Microsoft Office security feature bypass vulnerability that allows attackers to deliver specially crafted Office documents that bypass built-in Office protections…

Read more >

cve-2026-21509

Critical Fortinet Vulnerabilities Under Active Exploitation

Multiple critical vulnerabilities affecting Fortinet products are being actively exploited in the wild, primarily targeting FortiOS SSL VPN services and internet-facing security appliances. Several of…

Read more >

fortinet vulnerabilities

CVE-2025-26399: Critical SolarWinds Web Help Desk RCE

A critical vulnerability tracked as CVE-2025-26399 affects SolarWinds Web Help Desk (WHD), a widely used IT service management platform for ticketing and asset management. The…

Read more >

CVE-2025-26399

Critical Cisco Secure FMC Vulnerabilities Allow Root Access (CVE-2026-20079 & CVE-2026-20131)

Cisco has released security updates addressing two maximum-severity vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC) firewall management platforms.…

Read more >

CVE-2026-20079 & CVE-2026-20131
Under Cyber Attack?

Fill out the form and we will contact you immediately.