Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerability

Mozilla fixes high-severity Firefox and Thunderbird flaws in Firefox 150 and ESR updates

Updated 4d agoFirst seen Apr 8, 20265 sources

Mozilla released Firefox 150 and updated Firefox ESR branches to address multiple security vulnerabilities, prompting downstream advisories from Debian and the Canadian Centre for Cyber Security. The fixes cover Firefox versions prior to 150, Firefox ESR versions prior to 140.10 and 115.35, and include vulnerabilities tracked as CVE-2026-6768, CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. CVE-2026-6768 was described as a mitigation bypass in Firefox’s Networking: Cookies component and was assigned a CVSS 9.8 score, indicating potentially severe impact if left unpatched.

Mozilla also shipped related security fixes in Thunderbird 150, which uses Firefox’s web engine and addressed issues including a clickjacking and information disclosure flaw referenced in the Firefox advisories. Alongside the security patches, Mozilla’s releases included broad product updates such as privacy and platform changes in Firefox and improved encrypted-message search and OpenPGP features in Thunderbird. Government and Linux distribution advisories urged users and administrators to review Mozilla’s bulletins and apply the latest browser and mail client updates promptly.

Share:
Mozilla fixes high-severity Firefox and Thunderbird flaws in Firefox 150 and ESR updates
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 21, 20262mo ago

Thunderbird 150 released with security patches and feature updates

Thunderbird 150.0 was released with new features, bug fixes, and security patches affecting its web engine, including fixes tied to Firefox advisories. The release added encrypted message search, OpenPGP signature improvements, and PDF viewer enhancements.

Thunderbird 150 arrives with encrypted message search and OpenPGP improvements - Help Net Security

CVE-2026-6768 record updated with CVSS and CWE details

The CVE record for CVE-2026-6768 was updated to add a CVSS v3.1 vector, classify the weakness as CWE-288, and include references to a Mozilla Bugzilla entry and MFSA2026-30.

CVE-2026-6768 - Mitigation bypass in the Networking: Cookies component

Mozilla releases Firefox 150 and Firefox ESR security updates

Mozilla published security advisories for Firefox versions prior to 150, Firefox ESR versions prior to 140.10, and Firefox ESR versions prior to 115.35, and made the corresponding updates available. The fixes included vulnerabilities such as CVE-2026-6768, which was addressed in Firefox 150.

Mozilla security advisory (AV26-372) - Canadian Centre for Cyber Security
Apr 8, 20262mo ago

Debian releases firefox-esr security update DSA 6202-1

Debian published security advisory DSA 6202-1 for firefox-esr, announcing a security update for the package.

[SECURITY] [DSA 6202-1] firefox-esr security update
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.