Kaspersky ID:
KLA90962
Detect Date:
03/24/2026
Updated:
04/01/2026

Description

Multiple vulnerabilities were found in Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to cause denial of service, bypass security restrictions, execute arbitrary code, obtain sensitive information, gain privileges.

Below is a complete list of vulnerabilities:

  1. Out of bounds memory read vulnerability in JIT can be exploited to cause denial of service.
  2. Security vulnerability can be exploited to bypass security restrictions.
  3. Security vulnerability in WebRTC can be exploited to bypass security restrictions.
  4. Use after free vulnerability can be exploited to cause denial of service or execute arbitrary code.
  5. Information disclosure vulnerability can be exploited to obtain sensitive information.
  6. Memory safety vulnerability can be exploited to execute arbitrary code
  7. Type confusion vulnerability can be exploited to cause denial of service.
  8. Memory safety vulnerability can be exploited to execute arbitrary code.
  9. Denial of service vulnerability can be exploited remotely to cause denial of service.
  10. An elevation of privilege vulnerability can be exploited remotely to gain privileges.

Original advisories

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

CVE list

  • CVE-2025-59375
    critical
  • CVE-2026-4684
    critical
  • CVE-2026-4685
    critical
  • CVE-2026-4686
    critical
  • CVE-2026-4687
    critical
  • CVE-2026-4688
    critical
  • CVE-2026-4689
    critical
  • CVE-2026-4690
    critical
  • CVE-2026-4691
    critical
  • CVE-2026-4692
    critical
  • CVE-2026-4693
    critical
  • CVE-2026-4694
    critical
  • CVE-2026-4695
    critical
  • CVE-2026-4696
    critical
  • CVE-2026-4697
    critical
  • CVE-2026-4698
    critical
  • CVE-2026-4699
    critical
  • CVE-2026-4700
    critical
  • CVE-2026-4701
    critical
  • CVE-2026-4702
    critical
  • CVE-2026-4704
    critical
  • CVE-2026-4705
    critical
  • CVE-2026-4706
    critical
  • CVE-2026-4707
    critical
  • CVE-2026-4708
    critical
  • CVE-2026-4709
    critical
  • CVE-2026-4710
    critical
  • CVE-2026-4711
    critical
  • CVE-2026-4712
    critical
  • CVE-2026-4713
    critical
  • CVE-2026-4714
    critical
  • CVE-2026-4715
    critical
  • CVE-2026-4716
    critical
  • CVE-2026-4717
    critical
  • CVE-2026-4718
    critical
  • CVE-2026-4719
    critical
  • CVE-2026-4720
    critical
  • CVE-2026-4721
    critical

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Do you want to save your changes?
Your message has been sent successfully.