Product of Mozilla

Firefox

As of , 5 Mozilla Firefox vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2015-4495.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2015-4495Security Feature BypassMozilla FirefoxPatch this weekMetasploit module; EPSS 0.690.69
2CVE-2024-9680Use-After-FreeMozilla FirefoxPatch this weekRansomware use0.23
3CVE-2022-26485Use-After-FreeMozilla FirefoxPatch soon0.14
4CVE-2013-1675Information DisclosureMozilla FirefoxPatch soon0.07
5CVE-2022-26486Use-After-FreeMozilla FirefoxPatch soon0.02

Added each year

12342022: 4420222023: nonenone20232024: 1120242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20224
2023none
20241
2025none
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2024-9680 Mozilla FirefoxRansomware use: Unknown to Known.

Every change we recorded