Open Nav
Sign Up

CISA: Mozilla Releases Security Updates for Firefox and Thunderbird to Address Critical Vulnerabilities

Bar Refael

February 25, 2024

Mozilla has issued critical security updates for Firefox, Firefox ESR, and Thunderbird to address several vulnerabilities. These vulnerabilities, if exploited, could allow a cyber threat actor to take control of an affected system, leading to potential data theft, system compromise, or further network infiltration.

Details: 

The vulnerabilities addressed in these updates are varied in nature and include issues such as buffer overflows, use-after-free errors, and cross-site scripting (XSS) vulnerabilities. These vulnerabilities are particularly concerning as they could allow remote attackers to execute arbitrary code on the user’s system or manipulate the affected software in unintended ways.

Affected Products:

  • Firefox (versions prior to 110.0)
  • Firefox ESR (versions prior to 102.12)
  • Thunderbird (versions prior to 102.12)

Mitigation: 

Mozilla has released the following security advisories with details on the vulnerabilities and the necessary updates:

  • MFSA 2024-05 for Firefox: This advisory addresses multiple vulnerabilities in Firefox 110.0. Users are advised to update to Firefox 110.0 or later to mitigate these risks.
  • MFSA 2024-06 for Firefox ESR: This advisory covers several vulnerabilities in Firefox ESR 102.12. Users should update to Firefox ESR 102.12 or later to ensure protection.
  • MFSA 2024-07 for Thunderbird: This advisory details vulnerabilities in Thunderbird 102.12. It is recommended to update to Thunderbird 102.12 or later to address these security issues.

CISA Recommendations: 

The Cybersecurity and Infrastructure Security Agency (CISA) strongly encourages users and administrators to review the Mozilla Security Advisories and apply the necessary updates as soon as possible to prevent potential exploitation by cyber threat actors.

Stay safe and informed,

OP Innovate Research Team.

Resources highlights

WordPress CVE-2026-64638 Pre-Auth XSS Can Be Chained to RCE (XSS2Shell)

WordPress has released security updates to address a high-severity vulnerability that allows unauthenticated attackers to execute JavaScript in the context of a WordPress website and,…

Read more >

cve_2026_64638_xss2shell

ChainDrop npm Supply Chain Attack Compromises Hundreds of Packages and Steals Developer Credentials

A rapidly spreading software supply chain attack known as ChainDrop has compromised hundreds of packages in the npm ecosystem, including widely used caching libraries with…

Read more >

chaindrop_npm

N-able N-central Authentication Bypass Exploitation (CVE-2026-18577)

A high-severity authentication bypass vulnerability in N-able N-central is being actively exploited to compromise remote monitoring and management servers and gain access to downstream customer…

Read more >

cve-2026-18577_op

Cisco FMC Zero-Day CVE-2026-20316 Actively Exploited to Access Sensitive Data

Cisco has disclosed an actively exploited vulnerability in Cisco Secure Firewall software that allows unauthenticated remote attackers to gain access to affected systems using static…

Read more >

cve-2026-20316

Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

Check Point has released an urgent security update addressing three vulnerabilities affecting its Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating system products.…

Read more >

checkpoint_cve-2026-16232

WP2Shell WordPress Core RCE Exploited in the Wild (CVE-2026-63030 and CVE-2026-60137)

WordPress administrators should urgently patch two recently disclosed Core vulnerabilities collectively known as WP2Shell. When chained together, the flaws allow an unauthenticated attacker to execute…

Read more >

wp2shell
Under Cyber Attack?

Fill out the form and we will contact you immediately.