Skip to content

Products › Brands

Brand

Mozilla: actively exploited vulnerabilities

13 vulnerabilities in Mozilla products (Firefox) are in CISA’s catalog of exploited vulnerabilities. Last added: October 6, 2025.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Mozilla category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Firefox13 vulnerabilities, Browsers

Name used by CISA: Mozilla. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Mozilla list.

  1. Rank 1

    Mozilla FirefoxCVE-2010-3765

    Mozilla Multiple Products Remote Code Execution Vulnerability

    CVE from 2010, added in 2025

    CVSS severity 9.8critical

    Added Oct 6, 2025

  2. Rank 2

    Mozilla FirefoxCVE-2019-11708

    Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 10.0critical

    Added May 23, 2022

  3. Rank 3

    Mozilla FirefoxCVE-2024-9680

    Mozilla Firefox Use-After-Free Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Oct 15, 2024

  4. Rank 4

    Mozilla FirefoxCVE-2022-26486

    Mozilla Firefox Use-After-Free Vulnerability

    CVSS severity 9.6critical

    Added Mar 7, 2022

  5. Rank 5

    Mozilla FirefoxCVE-2015-4495

    Mozilla Firefox Security Feature Bypass Vulnerability

    CVE from 2015, added in 2022

    CVSS severity 8.8high

    Added May 25, 2022

  6. Rank 6

    Mozilla FirefoxCVE-2019-11707

    Mozilla Firefox and Thunderbird Type Confusion Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 8.8high

    Added May 23, 2022

  7. Rank 7

    Mozilla FirefoxCVE-2013-1690

    Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

    CVE from 2013, added in 2022

    CVSS severity 8.8high

    Added Mar 28, 2022

  8. Rank 8

    Mozilla FirefoxCVE-2022-26485

    Mozilla Firefox Use-After-Free Vulnerability

    CVSS severity 8.8high

    Added Mar 7, 2022

  9. Rank 9

    Mozilla FirefoxCVE-2019-17026

    Mozilla Firefox And Thunderbird Type Confusion Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 8.8high

    Added Nov 3, 2021

  10. Rank 10

    Mozilla FirefoxCVE-2020-6819

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    CVSS severity 8.1high

    Added Nov 3, 2021

Show 3 more vulnerabilities
  1. Rank 11

    Mozilla FirefoxCVE-2020-6820

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    CVSS severity 8.1high

    Added Nov 3, 2021

  2. Rank 12

    Mozilla FirefoxCVE-2016-9079

    Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

    CVE from 2016, added in 2023

    CVSS severity 7.5high

    Added Jun 22, 2023

  3. Rank 13

    Mozilla FirefoxCVE-2013-1675

    Mozilla Firefox Information Disclosure Vulnerability

    CVE from 2013, added in 2022

    CVSS severity 6.5medium

    Added Mar 3, 2022

Follow and verify

Get new Mozilla vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.