Multiples vulnérabilités dans les produits Mozilla (02 septembre 2026)
Mozilla has disclosed multiple vulnerabilities across its Firefox and Thunderbird products. These vulnerabilities range from data confidentiality issues and policy bypasses to denial-of-service conditions and privilege escalation. The affected products include various ESR (Extended Support Release) versions of Firefox and Thunderbird. The vulnerabilities are being addressed through security updates, and users are strongly advised to apply these patches promptly to mitigate potential risks.
Mozilla has identified and announced several security vulnerabilities impacting its Firefox and Thunderbird browsers. These vulnerabilities present a range of risks, including the potential for attackers to compromise user data, circumvent security policies, and cause denial-of-service conditions. Specifically, the vulnerabilities can lead to an attacker gaining elevated privileges, potentially allowing them to execute arbitrary code. The affected versions of Firefox ESR (Extended Support Release) include versions prior to 115.40, 140.15, 153.2, 155, and Thunderbird ESR versions prior to 140.15, 153.2, and 155. These vulnerabilities are being addressed through security updates, and Mozilla encourages users to install the latest patches immediately to ensure their systems are protected. The security advisories can be found at the links provided in the documentation section. The CVE identifiers associated with these vulnerabilities include CVE-2026-16365, CVE-2026-16371, CVE-2026-74952, CVE-2026-75874, CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126, CVE-2026-84127, CVE-2026-84128, CVE-2026-84129, CVE-2026-84130, CVE-2026-84131, CVE-2026-84132, CVE-2026-84133, CVE-2026-84134, CVE-2026-84135, CVE-2026-84136, CVE-2026-84137, CVE-2026-84138, CVE-2026-84139, CVE-2026-84140, CVE-2026-84141, CVE-2026-84142, CVE-2026-84143, CVE-2026-84144, CVE-2026-84145, and CVE-2026-84637, CVE-2026-84639, CVE-2026-84640, CVE-2026-84641, and CVE-2026-84642.