Open Nav
Sign Up

CISA: Mozilla Releases Security Updates for Firefox and Thunderbird to Address Critical Vulnerabilities

Bar Refael

February 25, 2024

Mozilla has issued critical security updates for Firefox, Firefox ESR, and Thunderbird to address several vulnerabilities. These vulnerabilities, if exploited, could allow a cyber threat actor to take control of an affected system, leading to potential data theft, system compromise, or further network infiltration.

Details: 

The vulnerabilities addressed in these updates are varied in nature and include issues such as buffer overflows, use-after-free errors, and cross-site scripting (XSS) vulnerabilities. These vulnerabilities are particularly concerning as they could allow remote attackers to execute arbitrary code on the user’s system or manipulate the affected software in unintended ways.

Affected Products:

  • Firefox (versions prior to 110.0)
  • Firefox ESR (versions prior to 102.12)
  • Thunderbird (versions prior to 102.12)

Mitigation: 

Mozilla has released the following security advisories with details on the vulnerabilities and the necessary updates:

  • MFSA 2024-05 for Firefox: This advisory addresses multiple vulnerabilities in Firefox 110.0. Users are advised to update to Firefox 110.0 or later to mitigate these risks.
  • MFSA 2024-06 for Firefox ESR: This advisory covers several vulnerabilities in Firefox ESR 102.12. Users should update to Firefox ESR 102.12 or later to ensure protection.
  • MFSA 2024-07 for Thunderbird: This advisory details vulnerabilities in Thunderbird 102.12. It is recommended to update to Thunderbird 102.12 or later to address these security issues.

CISA Recommendations: 

The Cybersecurity and Infrastructure Security Agency (CISA) strongly encourages users and administrators to review the Mozilla Security Advisories and apply the necessary updates as soon as possible to prevent potential exploitation by cyber threat actors.

Stay safe and informed,

OP Innovate Research Team.

Resources highlights

Next.js Critical Vulnerabilities Enable Unauthenticated RCE

Vercel has released security updates for two critical vulnerabilities in Next.js that could allow unauthenticated attackers to achieve remote code execution on vulnerable applications. The…

Read more >

next.js

Keycloak CVE-2026-18963 Enables Unauthenticated Account Takeover

A critical vulnerability in Keycloak could allow an unauthenticated remote attacker to take control of arbitrary user accounts through the platform's password recovery functionality. Tracked…

Read more >

cve-2026-18963

Elementor Pro CVE-2026-32475 Enables Unauthenticated File Upload and RCE

A critical vulnerability in the widely deployed Elementor Pro plugin for WordPress can allow unauthenticated attackers to bypass file-type restrictions, upload executable PHP files to…

Read more >

CVE-2026-32475

Windows IKE CVE-2026-33824 Exploited for Pre-Auth Remote Code Execution

A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE) is now being actively exploited. Tracked as CVE-2026-33824, the vulnerability is a…

Read more >

cve-2026-33824

VMware vCenter CVE-2026-59310 Actively Exploited for RCE and Persistent Access

Threat actors are actively exploiting CVE-2026-59310, a critical unauthenticated remote code execution vulnerability affecting VMware vCenter Server, with incident responders identifying compromises across dozens of…

Read more >

cve-2026-59310

ShieldBreak: Microsoft Defender 0-Day Leads to SYSTEM Privileges

A security researcher has released ShieldBreak, a new proof-of-concept exploit targeting Microsoft Defender that can elevate a low-privileged Windows user to NT AUTHORITY\SYSTEM on fully…

Read more >

shieldbreak
Under Cyber Attack?

Fill out the form and we will contact you immediately.