Open Nav
Sign Up

CISA: Mozilla Releases Security Updates for Firefox and Thunderbird to Address Critical Vulnerabilities

Bar Refael

February 25, 2024

Mozilla has issued critical security updates for Firefox, Firefox ESR, and Thunderbird to address several vulnerabilities. These vulnerabilities, if exploited, could allow a cyber threat actor to take control of an affected system, leading to potential data theft, system compromise, or further network infiltration.

Details: 

The vulnerabilities addressed in these updates are varied in nature and include issues such as buffer overflows, use-after-free errors, and cross-site scripting (XSS) vulnerabilities. These vulnerabilities are particularly concerning as they could allow remote attackers to execute arbitrary code on the user’s system or manipulate the affected software in unintended ways.

Affected Products:

  • Firefox (versions prior to 110.0)
  • Firefox ESR (versions prior to 102.12)
  • Thunderbird (versions prior to 102.12)

Mitigation: 

Mozilla has released the following security advisories with details on the vulnerabilities and the necessary updates:

  • MFSA 2024-05 for Firefox: This advisory addresses multiple vulnerabilities in Firefox 110.0. Users are advised to update to Firefox 110.0 or later to mitigate these risks.
  • MFSA 2024-06 for Firefox ESR: This advisory covers several vulnerabilities in Firefox ESR 102.12. Users should update to Firefox ESR 102.12 or later to ensure protection.
  • MFSA 2024-07 for Thunderbird: This advisory details vulnerabilities in Thunderbird 102.12. It is recommended to update to Thunderbird 102.12 or later to address these security issues.

CISA Recommendations: 

The Cybersecurity and Infrastructure Security Agency (CISA) strongly encourages users and administrators to review the Mozilla Security Advisories and apply the necessary updates as soon as possible to prevent potential exploitation by cyber threat actors.

Stay safe and informed,

OP Innovate Research Team.

Resources highlights

CVE-2026-46817: Critical Oracle E-Business Suite Vulnerability

A critical vulnerability in Oracle E-Business Suite is now being actively exploited in the wild. Tracked as CVE-2026-46817, the flaw affects the File Transmission component…

Read more >

cve-2026-46817-oracle-e-business

Cisco Unified CM Vulnerability CVE-2026-20230 Targeted After Public PoC Disclosure 

Cisco has disclosed and patched CVE-2026-20230, a critical SSRF vulnerability affecting Cisco Unified Communications Manager and Unified CM SME when the WebDialer service is enabled.…

Read more >

CVE-2026-20230

Microsoft Confirms Unpatched RoguePlanet Defender Zero-Day (CVE-2026-50656)

Microsoft has confirmed a new Microsoft Defender zero-day vulnerability tracked as CVE-2026-50656 and publicly referred to as RoguePlanet. The flaw affects the Microsoft Malware Protection…

Read more >

RoguePlanet_cve-2026-50656

FortiBleed Campaign Exposes Fortinet Firewall and VPN Credentials at Scale

A large-scale credential abuse campaign dubbed FortiBleed has reportedly affected tens of thousands of Fortinet firewall and VPN devices worldwide. Public reporting indicates that threat…

Read more >

fortibleed

Fortinet FortiSandbox Under Active Attack (CVE-2026-39813 & Others)

Threat actors are actively exploiting multiple critical vulnerabilities affecting Fortinet FortiSandbox. The reported activity involves three unauthenticated vulnerabilities: CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. These flaws are…

Read more >

cve-2026-39813

Critical Wazuh Manager Vulnerability Enables Alert Tampering and Security Evidence Deletion

A critical vulnerability has been disclosed in Wazuh Manager that could allow attackers to tamper with security data, delete alerts, and manipulate forensic evidence stored…

Read more >

wazuh manager vulnerability
Under Cyber Attack?

Fill out the form and we will contact you immediately.