Exploitation timeline
Threadlinqs has recorded 7 Mozilla CVEs published between and . The busiest month was 2026-07 (3 new CVEs). 1 of them (14%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 7 of 7 tracked Mozilla CVEs.
- CVE-2024-9680critical 9.8KEVRansomwareEPSS 30.8%
- CVE-2026-10702medium 4.3EPSS 0.6%
- CVE-2026-16405high 7.5EPSS 0.3%
- CVE-2026-15718medium 4.3EPSS 0.2%
- CVE-2026-84637critical 9.8EPSS 0.2%
- CVE-2026-84642high 7.5EPSS 0.1%
- CVE-2026-15719medium 5.4EPSS 0.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 7 CVEs; 2 distinct Mozilla products are affected. The most frequently affected:
- Firefox 5 CVEs
- Thunderbird 4 CVEs
Threat activity
52 tracked threat campaigns reference Mozilla products or exploit Mozilla CVEs; the 25 most recent are listed.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)HIGH
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)HIGH
- ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting PanelMEDIUM
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela BreachHIGH
- TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate TransparencyHIGH
- Known Techniques, Unknown Speed: Aqua Security on How Frontier AI Collapses the Container Attack ChainHIGH
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by SideHIGH
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser Fingerprinting Evasion GateHIGH
- ClickFix Attack Delivers Go-Based macOS Infostealer Targeting Cryptocurrency Wallets and CredentialsHIGH
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and MacSync CampaignHIGH
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-FiHIGH
- Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405)HIGH
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)HIGH
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via SteganographyHIGH
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 TokensHIGH
- MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal CredentialsHIGH
- MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session HijackingHIGH
- SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)HIGH
- TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR ChainHIGH
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17HIGH
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell BackdoorHIGH
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)CRITICAL
- TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer ChainHIGH
- macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App ReplacementHIGH
- CrashStealer: Native C++ macOS Infostealer Impersonating Apple's CrashReporter, Delivered via Notarized "Werkbit" Meeting-App LureHIGH
Threat actors targeting Mozilla
Named threat actors attributed to campaigns that involve Mozilla products or CVEs, with the number of linked campaigns:
How to prioritise Mozilla patching
This order follows the data Threadlinqs holds for Mozilla, not a generic severity checklist:
- 1 of 7 Mozilla CVEs (14%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2024-9680.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-10702 (0.6%), CVE-2026-16405 (0.3%), CVE-2026-15718 (0.2%).
- 2 CVEs score Critical and 2 High on CVSS v3 (maximum 9.8, average 6.9); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.