CyberMax
Home › Exploited CVEs

Mozilla known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 13 Mozilla CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2025-10-06), and 1 are known to be used in ransomware campaigns.

Mozilla CVEs added to CISA KEV per year
2021: 3202132022: 7202272023: 1202312024: 1202412025: 120251

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Mozilla products

Firefox and Thunderbird (6), Firefox (5), Multiple Products (1), Firefox, Firefox ESR, and Thunderbird (1).

All Mozilla CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2010-3765Multiple ProductsMultiple Products Remote Code Execution2025-10-062025-10-2783.2%–
CVE-2024-9680FirefoxFirefox Use-After-Free2024-10-152024-11-0523.2%Yes
CVE-2016-9079Firefox, Firefox ESR, and ThunderbirdFirefox, Firefox ESR, and Thunderbird Use-After-Free2023-06-222023-07-1387.4%–
CVE-2015-4495FirefoxFirefox Security Feature Bypass2022-05-252022-06-1568.6%–
CVE-2019-11708Firefox and ThunderbirdFirefox and Thunderbird Sandbox Escape2022-05-232022-06-1355.9%–
CVE-2019-11707Firefox and ThunderbirdFirefox and Thunderbird Type Confusion2022-05-232022-06-1337.7%–
CVE-2013-1690Firefox and ThunderbirdFirefox and Thunderbird Denial-of-Service2022-03-282022-04-1869.0%–
CVE-2022-26486FirefoxFirefox Use-After-Free2022-03-072022-03-212.3%–
CVE-2022-26485FirefoxFirefox Use-After-Free2022-03-072022-03-2114.3%–
CVE-2013-1675FirefoxFirefox Information Disclosure2022-03-032022-03-246.7%–
CVE-2020-6820Firefox and ThunderbirdFirefox And Thunderbird Use-After-Free2021-11-032022-05-037.1%–
CVE-2020-6819Firefox and ThunderbirdFirefox And Thunderbird Use-After-Free2021-11-032022-05-033.0%–
CVE-2019-17026Firefox and ThunderbirdFirefox And Thunderbird Type Confusion2021-11-032022-05-0346.3%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors