Vendor Exploitation Record

Mozilla (Firefox and Thunderbird) — Known Exploited Vulnerabilities

13 in CISA KEV · 1 ransomware-linked · as of 2026-08-31
In CISA KEV13 confirmed exploited
Ransomware-linked1 (8% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2025-10-06

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Mozilla (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Mozilla vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2010-3765Multiple ProductsMozilla Multiple Products Remote Code Execution Vulnerability2025-10-06
CVE-2024-9680FirefoxMozilla Firefox Use-After-Free Vulnerability2024-10-15ransomware
CVE-2016-9079Firefox, Firefox ESR, and ThunderbirdMozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability2023-06-22
CVE-2015-4495FirefoxMozilla Firefox Security Feature Bypass Vulnerability2022-05-25
CVE-2019-11707Firefox and ThunderbirdMozilla Firefox and Thunderbird Type Confusion Vulnerability2022-05-23
CVE-2019-11708Firefox and ThunderbirdMozilla Firefox and Thunderbird Sandbox Escape Vulnerability2022-05-23
CVE-2013-1690Firefox and ThunderbirdMozilla Firefox and Thunderbird Denial-of-Service Vulnerability2022-03-28
CVE-2022-26486FirefoxMozilla Firefox Use-After-Free Vulnerability2022-03-07
CVE-2022-26485FirefoxMozilla Firefox Use-After-Free Vulnerability2022-03-07
CVE-2013-1675FirefoxMozilla Firefox Information Disclosure Vulnerability2022-03-03
CVE-2020-6819Firefox and ThunderbirdMozilla Firefox And Thunderbird Use-After-Free Vulnerability2021-11-03
CVE-2020-6820Firefox and ThunderbirdMozilla Firefox And Thunderbird Use-After-Free Vulnerability2021-11-03
CVE-2019-17026Firefox and ThunderbirdMozilla Firefox And Thunderbird Type Confusion Vulnerability2021-11-03

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.