Privilege escalation in the WebRTC: Audio/Video component
Description
Privilege escalation in the WebRTC: Audio/Video component
AI Analyst Comment
Remediation
Update to patched version immediately. Review user permissions and access controls.
15 high and critical vulnerabilities covered by CVE Brief since 2025-11-13, each with independent analyst commentary.
← All vendors15 CVEs in the last 12 months
2 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Privilege escalation in the WebRTC: Audio/Video component
Privilege escalation in the WebRTC: Audio/Video component
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Security component
Privilege escalation in the Security component
Description Summary:
Mozilla Firefox and Thunderbird contain a vulnerability in the Security component that allows for privilege escalation.
Executive Summary:
Mozilla Firefox and Thunderbird are affected by a privilege escalation vulnerability in the security component that could allow an attacker to bypass intended security constraints.
Vulnerability Details
CVE-ID: CVE-2026-8970
Affected Software: Mozilla Firefox, Mozilla Thunderbird
Affected Versions: Versions prior to 140.11; fixed in 140.11 through 140.* and 151 and later.
Vulnerability: This vulnerability involves a flaw in the Security component that facilitates privilege escalation. The vulnerability requires user interaction (UI:R), typically occurring when a user visits a malicious site or opens a crafted message, allowing an attacker to escalate privileges within the application context.
Business Impact
Successful exploitation could allow an attacker to gain elevated privileges, potentially leading to full system compromise depending on the user's local permissions. With a CVSS score of 7.3, this flaw represents a significant risk to endpoint security, especially in environments where users have elevated system access.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 151 or later, or ensure the current version is within the patched 140.11+ range.
Proactive Monitoring: Monitor endpoint security logs for unexpected process execution or privilege changes associated with the browser or email client processes.
Compensating Controls: Enforce organizational policies that restrict the execution of browser-based scripts and utilize endpoint protection platforms (EPP) to detect malicious behavior triggered by browser exploitation.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of May 20, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The reliance on user interaction lowers the immediate risk compared to unauthenticated, remote code execution.
Analyst Recommendation
Mozilla users should update their software to the latest stable versions immediately to remediate the privilege escalation flaw. Organizations should use centralized software management tools to ensure all endpoints are updated to a non-vulnerable version of Firefox and Thunderbird to maintain a secure posture.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Enterprise Policies component
Privilege escalation in the Enterprise Policies component
Description Summary:
A privilege escalation vulnerability exists in the Enterprise Policies component of Mozilla Firefox and Thunderbird, potentially allowing full system compromise.
Executive Summary:
An enterprise policy privilege escalation vulnerability in Mozilla Firefox and Thunderbird poses a critical threat to system security and requires immediate remediation.
Vulnerability Details
CVE-ID: CVE-2026-8957
Affected Software: Mozilla Firefox and Mozilla Thunderbird
Affected Versions: Versions prior to 140.11, and versions between 140.11 and 151
Vulnerability: This vulnerability resides in the Enterprise Policies component, allowing an attacker to escalate privileges. It is a network-based attack that requires user interaction and impacts confidentiality, integrity, and availability.
Business Impact
With a CVSS score of 8.8, this vulnerability is highly critical. A successful exploit could lead to full system compromise, granting an attacker the ability to perform unauthorized administrative actions, steal sensitive enterprise credentials, or disrupt business operations.
Remediation Plan
Immediate Action: Apply the vendor-provided security updates by upgrading to version 151 or the 140.11 release immediately.
Proactive Monitoring: Review enterprise policy configurations and audit logs for any unauthorized changes or anomalous privilege elevation events.
Compensating Controls: Restrict browser execution environments using Group Policy or Mobile Device Management (MDM) tools to limit the potential impact of a successful privilege escalation.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of May 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's high CVSS score, however, indicates that it is a significant target for potential exploitation.
Analyst Recommendation
Given the potential for full system compromise, this CVE must be treated with the highest urgency. Organizations should prioritize the deployment of the patch across all enterprise endpoints to mitigate the risk of privilege escalation.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the DOM: Workers component
Privilege escalation in the DOM: Workers component
Description Summary:
A privilege escalation vulnerability exists in the DOM: Workers component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to execute arbitrary code.
Executive Summary:
A privilege escalation flaw in the DOM: Workers component of Mozilla Firefox and Thunderbird presents a critical risk of full system compromise through user-assisted interaction.
Vulnerability Details
CVE-ID: CVE-2026-8955
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Versions prior to 140.11, and versions between 140.11 and 151.
Vulnerability: This is a privilege escalation vulnerability within the DOM: Workers component. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates that while the attack is network-accessible, it requires user interaction, such as visiting a malicious webpage or opening a crafted message.
Business Impact
Successful exploitation of this vulnerability could lead to total system compromise, allowing an attacker to execute code with the privileges of the affected application. Given the CVSS score of 8.8, this poses a significant risk to data confidentiality, integrity, and availability, potentially facilitating lateral movement or data exfiltration.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Thunderbird to version 151 or later to ensure the vulnerability is patched.
Proactive Monitoring: Monitor endpoint logs for unusual child processes spawned by browser or mail client activities.
Compensating Controls: Utilize endpoint protection platforms (EPP) to block known malicious payloads and restrict browser execution permissions where possible.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of May 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's high severity is driven by its potential for full technical impact despite the requirement for user interaction.
Analyst Recommendation
This vulnerability represents a significant security risk due to the potential for privilege escalation within widely deployed software. Administrators should prioritize the deployment of the latest updates for both Firefox and Thunderbird across all workstations to mitigate the risk of unauthorized code execution.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Application Update component
Privilege escalation in the Application Update component
Description Summary:
A privilege escalation vulnerability exists in the Application Update component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain unauthorized system access.
Executive Summary:
A critical privilege escalation vulnerability in the Application Update component of Mozilla Firefox and Thunderbird could allow an attacker to achieve full system control.
Vulnerability Details
CVE-ID: CVE-2026-8952
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: All versions prior to 151.
Vulnerability: The vulnerability resides in the Application Update component and allows for privilege escalation. The CVSS vector (AV:N/AC:L/PR:N/UI:R) confirms that the vulnerability is exploitable via network-based vectors, requiring user interaction to trigger the update mechanism.
Business Impact
A successful exploit would allow an attacker to escalate privileges, potentially leading to a complete compromise of the host system. With a CVSS score of 8.8, the potential for unauthorized data access and system disruption makes this a high-priority remediation item for all enterprise environments.
Remediation Plan
Immediate Action: Update both Mozilla Firefox and Thunderbird to version 151 or later immediately.
Proactive Monitoring: Review application update logs and system integrity monitoring tools for unauthorized modifications during the update process.
Compensating Controls: Enforce strict user access controls and use endpoint security solutions to monitor for anomalous system-level changes initiated by update processes.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of May 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is inherently dangerous because it targets the update mechanism, which is typically trusted by the system.
Analyst Recommendation
Given the critical nature of privilege escalation, immediate patching is required to prevent potential system-level exploitation. Organizations should ensure their update management policies are enforced to capture the latest versions of these applications across the fleet.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Debugger component
Privilege escalation in the Debugger component
Description Summary:
A privilege escalation vulnerability exists in the Debugger component of Mozilla Firefox and Thunderbird, allowing potential unauthorized system control.
Executive Summary:
A critical privilege escalation vulnerability in the Mozilla Debugger component exposes Firefox and Thunderbird users to significant security risks.
Vulnerability Details
CVE-ID: CVE-2026-6769
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Versions prior to 140.10 and 150
Vulnerability: The vulnerability resides within the Debugger component, where a flaw enables privilege escalation. As indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:R), the attack is unauthenticated but requires user interaction, such as visiting a malicious webpage.
Business Impact
The ability to escalate privileges within the browser or email client environment poses a severe risk to organizational data integrity and system confidentiality. Given the CVSS score of 8.8, this flaw could allow an attacker to execute arbitrary code with the permissions of the application user, potentially leading to full system compromise. Such an incident could result in significant data exfiltration and loss of trust in internal communication channels.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Thunderbird to version 150 or the ESR 140.10 release immediately.
Proactive Monitoring: Monitor endpoint logs for suspicious process spawning or unexpected child processes originating from the browser or email client.
Compensating Controls: Deploy endpoint protection solutions that restrict browser-based script execution and enforce strict user privilege management to limit the blast radius of a successful exploit.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of April 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's requirement for user interaction provides a slight barrier to mass exploitation, but the severity of the impact necessitates prompt patching.
Analyst Recommendation
This vulnerability presents a high risk due to the potential for privilege escalation within widely deployed software. Security teams should prioritize the deployment of the provided patches across all workstations and servers running Firefox or Thunderbird to eliminate the attack vector. Failure to update may leave systems susceptible to malicious actors seeking to leverage browser-based vulnerabilities for further network infiltration.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Networking component
Privilege escalation in the Networking component
Description Summary:
A privilege escalation vulnerability exists in the networking component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated permissions.
Executive Summary:
A privilege escalation vulnerability in the networking component of Mozilla Firefox and Thunderbird poses a high risk of unauthorized system access.
Vulnerability Details
CVE-ID: CVE-2026-6761
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Versions prior to 140.10 (ESR) and 150
Vulnerability: This vulnerability involves a flaw in the networking component that permits privilege escalation. The vulnerability requires user interaction, such as clicking a malicious link, and can be triggered by an unauthenticated remote attacker.
Business Impact
The exploitation of this vulnerability could lead to a complete compromise of the affected client application, potentially allowing unauthorized code execution within the user context. With a CVSS score of 8.8, this flaw represents a significant risk to organizational endpoints, which could be leveraged to bypass security controls or exfiltrate sensitive data.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 150 or the ESR 140.10 release immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected networking activity originating from web browsers or email clients.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block unauthorized privilege escalation attempts on user workstations.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of April 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's requirement for user interaction slightly reduces its exploitability, but the high severity necessitates prompt patching.
Analyst Recommendation
Given the potential for privilege escalation and the high CVSS rating, organizations should prioritize the deployment of the provided updates across all managed endpoints. Failure to remediate this vulnerability leaves users exposed to potential remote code execution attacks that could lead to full system compromise.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Graphics: WebRender component
Privilege escalation in the Graphics: WebRender component
Description Summary:
A privilege escalation vulnerability exists in the Graphics: WebRender component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to achieve full system impact.
Executive Summary:
A critical privilege escalation vulnerability in the Graphics: WebRender component of Mozilla Firefox and Thunderbird exposes users to potential system compromise.
Vulnerability Details
CVE-ID: CVE-2026-6750
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Versions prior to Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10
Vulnerability: This is a privilege escalation flaw located within the WebRender graphics component. The vulnerability is exploitable by an unauthenticated, remote attacker who lures a user into interacting with malicious content, as indicated by the CVSS vector requiring user interaction.
Business Impact
The vulnerability carries a high CVSS score of 8.8, reflecting the potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow a remote attacker to execute arbitrary code or escalate privileges within the context of the application, leading to unauthorized access to sensitive user data or complete compromise of the workstation.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Thunderbird to the identified patched versions (150, or the respective ESR releases 115.35/140.10) immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected modifications to system files originating from the browser or email client processes.
Compensating Controls: Ensure that browser security settings, such as sandboxing, remain enabled and verify that endpoint protection solutions are configured to detect known malicious patterns associated with browser-based exploits.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of April 22, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's requirement for user interaction provides a slight barrier to entry, but the severity of the impact necessitates prompt patching across all organizational endpoints.
Analyst Recommendation
Given the critical nature of this privilege escalation, all IT administrators should prioritize the deployment of the latest security updates for Mozilla Firefox and Thunderbird. Failure to patch these browsers leaves workstations vulnerable to high-impact attacks, and immediate action is required to maintain a secure computing environment.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the IPC component
Privilege escalation in the IPC component
Description Summary:
A privilege escalation vulnerability exists in the Inter-Process Communication (IPC) component of Mozilla Firefox and Thunderbird, potentially allowing full system compromise.
Executive Summary:
A critical privilege escalation vulnerability in the IPC component of Mozilla Firefox and Thunderbird enables attackers to gain elevated system permissions.
Vulnerability Details
CVE-ID: CVE-2026-4722
Affected Software: Mozilla Firefox and Mozilla Thunderbird
Affected Versions: All versions prior to 149
Vulnerability: This is a privilege escalation flaw within the IPC component that can be triggered by an unauthenticated attacker, provided they can induce a user to interact with malicious content. The vulnerability leverages the browser's communication architecture to bypass standard security boundaries and execute arbitrary actions with higher privileges.
Business Impact
Successful exploitation of this vulnerability allows an attacker to gain unauthorized control over the affected application, leading to potential data exfiltration, unauthorized modification of user data, or arbitrary code execution. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to a total compromise of the host system. Such an event would result in significant operational disruption and severe reputational damage to the organization.
Remediation Plan
Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 149 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning activities or unexpected IPC communication patterns originating from browser-related services.
Compensating Controls: Deploy browser-based security policies that restrict cross-origin requests and employ endpoint detection and response tools to identify and block unauthorized privilege elevation attempts.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of March 26, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is considered inherently dangerous due to its potential to grant an attacker full control over the browser environment.
Analyst Recommendation
The severity of this vulnerability necessitates an immediate organization-wide update to Mozilla Firefox and Thunderbird version 149. Administrators should prioritize deployment of these patches to all workstations and servers to mitigate the risk of remote code execution or privilege escalation. Failure to update leaves systems exposed to potential exploitation that could bypass standard security controls.
Update to patched version immediately. Review user permissions and access controls.
A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird. Successful exploitation could allow an att...
A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird. Successful exploitation could allow an attacker to gain elevated permissions.
Description Summary:
A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird. Successful exploitation could allow an attacker to gain elevated permissions.
Executive Summary:
Mozilla Firefox and Thunderbird are vulnerable to a critical privilege escalation flaw within the Netmonitor component, potentially allowing for unauthorized access and system compromise.
Vulnerability Details
CVE-ID: CVE-2026-4717
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9
Vulnerability: This vulnerability involves a privilege escalation flaw located in the Netmonitor component. It likely allows an unauthenticated or low-privileged process to gain higher-level access within the application context.
Business Impact
The potential for privilege escalation in a widely used web browser and email client poses a significant risk to organizational data integrity. An attacker could leverage this flaw to bypass security boundaries, leading to unauthorized data access or the execution of administrative actions. The CVSS score of 9.8 justifies a critical severity rating, as it indicates a high probability of successful exploitation with devastating consequences for endpoint security.
Remediation Plan
Immediate Action: Update Mozilla Firefox to version 149 or higher, Firefox ESR to version 140.9 or higher, and Thunderbird to version 149 or 140.9 or higher immediately.
Proactive Monitoring: Security teams should monitor for unusual application crashes or unauthorized attempts to access developer tools (Netmonitor) within the environment.
Compensating Controls: Ensure that endpoint protection platforms (EPP) are active and configured to detect anomalous process behavior originating from browser components.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Mar 24, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw and its high CVSS score, the potential for exploitation is high.
Analyst Recommendation
This vulnerability represents a critical threat to the desktop environment due to the high privileges an attacker could obtain. It is imperative that all affected instances of Firefox and Thunderbird are updated to the latest patched versions without delay. Failure to remediate could result in a total compromise of the affected workstations.
Update Privilege Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
CyberArk Endpoint Privilege Manager Agent through 25
CyberArk Endpoint Privilege Manager Agent through 25
Description Summary:
The CyberArk Endpoint Privilege Manager (EPM) Agent is susceptible to a high-severity vulnerability that may allow for the bypass of security controls or unauthorized privilege escalation.
Executive Summary:
A vulnerability in the CyberArk Endpoint Privilege Manager Agent could allow an attacker to bypass critical security enforcement mechanisms on protected endpoints.
Vulnerability Details
CVE-ID: CVE-2025-66374
Affected Software: CyberArk Endpoint Privilege Manager Agent
Affected Versions: Through version 25
Vulnerability: The vulnerability exists within the agent component of the CyberArk EPM solution. While the specific mechanism is not detailed, it involves a failure in the enforcement of privilege policies, which an authenticated local user can exploit to circumvent security restrictions.
Business Impact
This vulnerability is particularly critical as it affects a tool specifically designed to manage and restrict privileges. A successful exploit allows an attacker to regain the very privileges the software is intended to block, leading to unauthorized software installation and potential access to sensitive corporate data. The CVSS score of 7.8 underscores the High risk associated with compromising a core security product.
Remediation Plan
Immediate Action: Upgrade the CyberArk EPM Agent to the latest patched version (post-version 25) as recommended in the CyberArk security portal.
Proactive Monitoring: Review EPM logs for policy bypass alerts and monitor for "Unknown" or "Unmanaged" applications running with administrative tokens.
Compensating Controls: Implement secondary layers of defense, such as AppLocker or Windows Defender Application Control (WDAC), to provide redundancy in case the primary EPM agent is compromised.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 5, 2026, there is no public information indicating active exploitation of this vulnerability. Security researchers frequently target privilege management tools, making the development of a private exploit highly likely.
Analyst Recommendation
CyberArk EPM is a foundational security control; any vulnerability within its agent must be addressed with the highest urgency. Organizations should initiate an immediate deployment of the updated agent to all managed endpoints to maintain the integrity of their least-privilege architecture.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally
Description Summary:
A privilege context switching error in Windows Administrator Protection allows a local attacker with authorized access to escalate privileges.
Executive Summary:
A vulnerability in the Windows Administrator Protection feature allows an authenticated local attacker to escalate privileges, posing a high risk to system integrity.
Vulnerability Details
CVE-ID: CVE-2025-60721
Affected Software: Microsoft Windows 11
Affected Versions: 10.0.26100.0 up to 10.0.26100.7171 and 10.0.26200.0 up to 10.0.26200.7171
Vulnerability: This is a privilege context switching error (CWE-270) within the Windows Administrator Protection component that enables a locally authenticated user to perform unauthorized privilege escalation.
Business Impact
Successful exploitation of this vulnerability grants an attacker elevated administrative rights on the local machine. This compromise allows for full system control, potential data exfiltration, or the installation of persistent malicious software, justifying the high CVSS score of 7.8.
Remediation Plan
Immediate Action: Apply the security updates provided by Microsoft in the November 2025 patch cycle to update Windows 11 to the corrected build versions.
Proactive Monitoring: Audit local system logs for unauthorized attempts to invoke administrative processes or unexpected changes to user group memberships.
Compensating Controls: Enforce the principle of least privilege for all local users to minimize the potential impact of an account being used as an initial vector for local escalation.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of November 12, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw requires the attacker to already possess local access, which somewhat limits the attack surface for remote threats.
Analyst Recommendation
Given the potential for full system compromise, this vulnerability should be prioritized within standard maintenance windows. Organizations should deploy the relevant Microsoft security updates across all affected Windows 11 instances immediately to remediate the context switching flaw and prevent unauthorized privilege escalation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Privilege escalation in the Netmonitor component
Privilege escalation in the Netmonitor component
Description Summary:
A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated permissions.
Executive Summary:
A critical privilege escalation flaw in the Netmonitor component of Mozilla Firefox and Thunderbird exposes users to potential security compromises and requires immediate updates.
Vulnerability Details
CVE-ID: CVE-2025-14329
Affected Software: Mozilla Firefox and Mozilla Thunderbird
Affected Versions: Versions prior to 140.6 and 146
Vulnerability: This is a privilege escalation vulnerability within the Netmonitor component. Based on the CVSS vector (PR:N, UI:R), the attack is unauthenticated but requires user interaction to exploit.
Business Impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to full system compromise if exploited. Successful exploitation allows an attacker to gain unauthorized privileges, potentially resulting in data exfiltration, the installation of malicious software, or unauthorized control over the affected application.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Thunderbird to version 146 or the ESR version 140.6 immediately to apply the necessary security patches.
Proactive Monitoring: Review browser and application logs for unusual Netmonitor activity or unexpected privilege changes within the application environment.
Compensating Controls: Ensure that users operate with the principle of least privilege, limiting the potential impact of an application-level compromise on the underlying operating system.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of December 10, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's requirement for user interaction provides a slight barrier to entry, but the potential for total impact makes patching essential.
Analyst Recommendation
Given the high CVSS score and the nature of privilege escalation, this vulnerability poses a significant risk to organizational endpoints. Security teams should prioritize the deployment of the Mozilla updates across all managed devices. Failure to patch these applications leaves users vulnerable to potential code execution and system-wide security breaches.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the Netmonitor component
Privilege escalation in the Netmonitor component
Description Summary:
A privilege escalation vulnerability exists in the Netmonitor component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated control.
Executive Summary:
A critical privilege escalation vulnerability in the Netmonitor component of Mozilla Firefox and Thunderbird exposes users to potential system compromise.
Vulnerability Details
CVE-ID: CVE-2025-14328
Affected Software: Mozilla Firefox and Mozilla Thunderbird
Affected Versions: Versions prior to 140.6 and 146
Vulnerability: The vulnerability exists within the Netmonitor component of the affected applications. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:R), this flaw can be triggered by an unauthenticated attacker through user interaction.
Business Impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of risk to organizational security. Successful exploitation could lead to unauthorized privilege escalation, allowing an attacker to bypass security boundaries, access sensitive data, or perform actions with the permissions of the affected user, potentially resulting in significant reputational damage and data loss.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 140.6 or 146, or the latest available stable release, to apply the necessary security fixes.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unauthorized attempts to access sensitive system files following browser updates.
Compensating Controls: Ensure that endpoint protection software is active and configured to block malicious scripts, and enforce the principle of least privilege for all local user accounts to limit the potential impact of successful escalation.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of December 10, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the vulnerability is highly severe, the requirement for user interaction provides a slight barrier to immediate exploitation.
Analyst Recommendation
Given the high CVSS score and the critical nature of privilege escalation flaws in web browsers, immediate remediation is required. Organizations should prioritize patching all instances of Firefox and Thunderbird across their infrastructure to eliminate this exposure and prevent potential exploitation by malicious actors.
Update to patched version immediately. Review user permissions and access controls.
Privilege escalation in the DOM: Notifications component
Privilege escalation in the DOM: Notifications component
Description Summary:
A privilege escalation vulnerability exists in the Notifications component of the DOM in Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain elevated privileges.
Executive Summary:
A critical privilege escalation vulnerability in Mozilla Firefox and Thunderbird could allow an attacker to bypass security controls and gain unauthorized elevated access.
Vulnerability Details
CVE-ID: CVE-2025-14323
Affected Software: Mozilla Firefox and Mozilla Thunderbird
Affected Versions: Versions prior to 146, 115.31 (ESR), and 140.6 (ESR)
Vulnerability: The flaw resides in the DOM Notifications component, which fails to properly enforce privilege boundaries. Exploitation requires user interaction via a network-based vector, allowing an unauthenticated remote attacker to gain elevated privileges within the application context.
Business Impact
Successful exploitation of this vulnerability can lead to a complete compromise of the affected client application, potentially resulting in unauthorized data access or the execution of arbitrary code within the user session. Given the CVSS score of 8.8, this vulnerability represents a significant risk to organizational endpoints, necessitating immediate attention to prevent potential system-wide security breaches.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Thunderbird to version 146 or higher, or the applicable Extended Support Release (ESR) versions 115.31 or 140.6, to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution or attempts to access restricted system resources originating from the browser or email client.
Compensating Controls: While no direct virtual patch exists, enforcing strict browser security policies and limiting user permissions on local workstations can reduce the potential blast radius of an exploited client-side application.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of December 10, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is considered highly exploitable due to the nature of DOM-based components, requiring only standard user interaction to trigger.
Analyst Recommendation
Organizations must prioritize the deployment of the provided security updates across all managed instances of Firefox and Thunderbird. Because this vulnerability allows for privilege escalation, delay in patching increases the risk of successful weaponization by threat actors who may target vulnerable browsers for initial access or lateral movement.
Update to patched version immediately. Review user permissions and access controls.
Description Summary:
A privilege escalation vulnerability exists in the WebRTC Audio/Video component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote attackers to compromise the system.
Executive Summary:
A privilege escalation flaw in the WebRTC component of Mozilla Firefox and Thunderbird exposes users to potential system compromise via remote interaction.
Vulnerability Details
CVE-ID: CVE-2026-8972
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Versions prior to 151
Vulnerability: This vulnerability resides in the WebRTC Audio/Video processing component. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates that an unauthenticated attacker can trigger this flaw by enticing a user to interact with malicious content.
Business Impact
The ability for an attacker to escalate privileges can lead to a full system compromise, resulting in unauthorized data access, execution of malicious code, and complete loss of system integrity. With a CVSS score of 8.8, this high-severity vulnerability poses a significant risk to organizational endpoints and requires immediate attention to prevent lateral movement or data exfiltration.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 151 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected spikes in WebRTC-related activity.
Compensating Controls: Ensure browser security settings are strictly enforced via Group Policy or MDM, and consider disabling WebRTC if it is not a required business function.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of May 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While exploitation requires user interaction, the potential impact of privilege escalation makes this a high priority for patching.
Analyst Recommendation
Given the high CVSS score and the critical nature of privilege escalation flaws in web browsers, administrators must prioritize the deployment of the version 151 update across all managed environments. Timely patching is the most effective defense against this vulnerability.