BrowserShield

Version security report

Firefox 137 security vulnerabilities

These public CVE records overlap Firefox major version 137. Matching is based on disclosed version ranges, not an exploit test.

709

public CVEs overlapping this major version

CVE list

CVE-2026-75874

Critical CVSS 10.0

Sandbox escape in the Remote Settings Client component.

Fixed in 154

CVE-2026-4725

Critical CVSS 10.0

Sandbox escape due to use-after-free in the Graphics: Canvas2D component.

Fixed in 149

CVE-2026-4692

Critical CVSS 10.0

Sandbox escape in the Responsive Design Mode component.

Fixed in 149

CVE-2026-4689

Critical CVSS 10.0

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component.

Fixed in 149

CVE-2026-4688

Critical CVSS 10.0

Sandbox escape due to use-after-free in the Disability Access APIs component.

Fixed in 149

CVE-2026-2778

Critical CVSS 10.0

Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component.

Fixed in 148

CVE-2026-2776

Critical CVSS 10.0

Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software.

Fixed in 148

CVE-2026-2768

Critical CVSS 10.0

Sandbox escape in the Storage: IndexedDB component.

Fixed in 148

CVE-2026-2761

Critical CVSS 10.0

Sandbox escape in the Graphics: WebRender component.

Fixed in 148

CVE-2026-2760

Critical CVSS 10.0

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component.

Fixed in 148

CVE-2026-16367

Critical CVSS 10.0

Sandbox escape due to invalid pointer in the Disability Access APIs component.

Fixed in 153

CVE-2026-0881

Critical CVSS 10.0

Sandbox escape in the Messaging System component.

Fixed in 147

CVE-2026-8956

Critical CVSS 9.8

Integer overflow in the Networking: JAR component.

Fixed in 151

CVE-2026-84143

Critical CVSS 9.8

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.

Fixed in 155

CVE-2026-84142

Critical CVSS 9.8

Internally found bugs present in Thunderbird 154.

Fixed in 155

CVE-2026-84141

Critical CVSS 9.8

Integer overflow in the Graphics: ImageLib component.

Fixed in 155

CVE-2026-84140

Critical CVSS 9.8

Site isolation issue in the DOM: Navigation component.

Fixed in 155

CVE-2026-84134

Critical CVSS 9.8

Other issue in the Profile Backup component.

Fixed in 155

CVE-2026-84133

Critical CVSS 9.8

Site isolation issue in the DOM: Push Subscriptions component.

Fixed in 155

CVE-2026-84129

Critical CVSS 9.8

Site isolation issue in the DOM: Navigation component.

Fixed in 155

CVE-2026-8401

Critical CVSS 9.8

Sandbox escape in the Profile Backup component.

Fixed in 150.0.3

CVE-2026-8094

Critical CVSS 9.8

Other issue in the WebRTC component.

Fixed in 140.10.2

CVE-2026-8091

Critical CVSS 9.8

Incorrect boundary conditions in the Audio/Video: Playback component.

Fixed in 150

CVE-2026-74990

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 140.

Fixed in 154

CVE-2026-74989

Critical CVSS 9.8

Internally found bugs present in Thunderbird 153.

Fixed in 154

CVE-2026-74988

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 153.

Fixed in 154

CVE-2026-74987

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 140.

Fixed in 154

CVE-2026-74985

Critical CVSS 9.8

Privilege escalation in the Enterprise Policies component.

Fixed in 154

CVE-2026-74979

Critical CVSS 9.8

Mitigation bypass in the Add-ons Manager component.

Fixed in 154

CVE-2026-74964

Critical CVSS 9.8

Integer overflow in the Graphics component.

Fixed in 154

CVE-2026-74944

Critical CVSS 9.8

Use-after-free in the DOM: Core & HTML component.

Fixed in 154

CVE-2026-74943

Critical CVSS 9.8

Use-after-free in the Graphics: ImageLib component.

Fixed in 154

CVE-2026-74940

Critical CVSS 9.8

Use-after-free in the Graphics: Text component.

Fixed in 154

CVE-2026-74936

Critical CVSS 9.8

Use-after-free in the JavaScript: WebAssembly component.

Fixed in 154

CVE-2026-6771

Critical CVSS 9.8

Mitigation bypass in the DOM: Security component.

Fixed in 150

CVE-2026-6768

Critical CVSS 9.8

Mitigation bypass in the Networking: Cookies component.

Fixed in 150

CVE-2026-6760

Critical CVSS 9.8

Mitigation bypass in the Networking: Cookies component.

Fixed in 150

CVE-2026-6748

Critical CVSS 9.8

Uninitialized memory in the Audio/Video: Web Codecs component.

Fixed in 150

CVE-2026-5735

Critical CVSS 9.8

Memory safety bugs present in Firefox 149.

Fixed in 149.0.2

CVE-2026-5734

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 140.

Fixed in 149.0.2

CVE-2026-5731

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 115.

Fixed in 149.0.2

CVE-2026-4729

Critical CVSS 9.8

Memory safety bugs present in Firefox 148 and Thunderbird 148.

Fixed in 149

CVE-2026-4723

Critical CVSS 9.8

Use-after-free in the JavaScript Engine component.

Fixed in 149

CVE-2026-4721

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 115.

Fixed in 149

CVE-2026-4720

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 140.

Fixed in 149

CVE-2026-4717

Critical CVSS 9.8

Privilege escalation in the Netmonitor component.

Fixed in 149

CVE-2026-4711

Critical CVSS 9.8

Use-after-free in the Widget: Cocoa component.

Fixed in 149

CVE-2026-4710

Critical CVSS 9.8

Incorrect boundary conditions in the Audio/Video component.

Fixed in 149

CVE-2026-4705

Critical CVSS 9.8

Undefined behavior in the WebRTC: Signaling component.

Fixed in 149

CVE-2026-4702

Critical CVSS 9.8

JIT miscompilation in the JavaScript Engine component.

Fixed in 149

CVE-2026-4701

Critical CVSS 9.8

Use-after-free in the JavaScript Engine component.

Fixed in 149

CVE-2026-4700

Critical CVSS 9.8

Mitigation bypass in the Networking: HTTP component.

Fixed in 149

CVE-2026-4698

Critical CVSS 9.8

JIT miscompilation in the JavaScript Engine: JIT component.

Fixed in 149

CVE-2026-4696

Critical CVSS 9.8

Use-after-free in the Layout: Text and Fonts component.

Fixed in 149

CVE-2026-4691

Critical CVSS 9.8

Use-after-free in the CSS Parsing and Computation component.

Fixed in 149

CVE-2026-2807

Critical CVSS 9.8

Memory safety bugs present in Firefox 147 and Thunderbird 147.

Fixed in 148

CVE-2026-2805

Critical CVSS 9.8

Invalid pointer in the DOM: Core & HTML component.

Fixed in 148

CVE-2026-2800

Critical CVSS 9.8

Spoofing issue in the WebAuthn component in Firefox for Android.

Fixed in 148

CVE-2026-2799

Critical CVSS 9.8

Use-after-free in the DOM: Core & HTML component.

Fixed in 148

CVE-2026-2797

Critical CVSS 9.8

Use-after-free in the JavaScript: GC component.

Fixed in 148

Showing the highest-severity 60 of 709 records.

Check my browser