Product of Mozilla

Firefox and Thunderbird

As of , 6 Mozilla Firefox and Thunderbird vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2013-1690.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2013-1690Denial-of-ServiceMozilla Firefox and ThunderbirdPatch this weekMetasploit module; EPSS 0.69; verified Exploit-DB entry0.69
2CVE-2019-11708Sandbox EscapeMozilla Firefox and ThunderbirdPatch this weekEPSS 0.560.56
3CVE-2019-11707Type ConfusionMozilla Firefox and ThunderbirdPatch soonVerified Exploit-DB entry0.38
4CVE-2019-17026Type ConfusionMozilla Firefox and ThunderbirdPatch soon0.46
5CVE-2020-6820Use-After-FreeMozilla Firefox and ThunderbirdPatch soon0.07
6CVE-2020-6819Use-After-FreeMozilla Firefox and ThunderbirdPatch soon0.03

Added each year

1232021: 3320212022: 3320222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20213
20223
2023none
2024none
2025none
2026none

Used in ransomware