Update Firefox and Thunderbird: 78 flaws fixed

Published

Mozilla has shipped its September security updates for Firefox and Thunderbird, and the seven advisories behind them list 78 distinct CVE identifiers between them. The most serious impact Mozilla flags is remote code execution, which means a crafted page or message can run an attacker's code on the computer that opens it.

That is a large batch, and it lands in the same week as Chrome's own round of 42 fixes.

Which builds are safe

The release covers an unusually wide spread of trains, because Mozilla is maintaining three extended support branches in parallel with the current one. You are covered on Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16 or Firefox ESR 153.3, and on Thunderbird 140.16, Thunderbird 153.3 or Thunderbird 156. Anything below those numbers is affected.

Hong Kong's HKCERT, which relayed the release in a bulletin on 17 September, lists the combined impact as remote code execution, denial of service, elevation of privilege, security restriction bypass, information disclosure and spoofing. It publishes no severity scores, and it does not break the 78 identifiers down by product.

The count is not the story

It is worth saying plainly what a number like 78 does and does not mean. It is the union of identifiers across seven separate advisories covering four Firefox trains and three Thunderbird builds, not the number of holes in any one of them, and the same identifier can appear on several of those advisories. A high total says a great deal about how much code Mozilla is auditing and very little about how exposed any individual user was.

Nobody outside Mozilla has published exploitation detail for these, and nothing in the release indicates that any of them is being used in attacks. Mozilla's own advisories, numbered mfsa2026-90 through mfsa2026-96, are the only place the per-flaw severity ratings and the researcher credits live. If you need to know whether a specific identifier reaches your estate, the Firefox 156 advisory is the entry point and the neighbouring numbers cover the ESR and Thunderbird builds.

Restart the application, not just the tab

Firefox and Thunderbird both fetch updates in the background on default settings, but a downloaded build does nothing until the application is restarted, and that is the step people skip. Check the version on the About screen afterwards. Managed fleets that pin an ESR branch should confirm which of the three they are on before pushing, because the fixed version is different for each one.

Organizations that standardised on another browser are not exempt either. Thunderbird sits on plenty of desktops that never open Firefox, and it is patched on the same cycle, the same way Edge takes its own monthly round. Mail clients tend to fall off the patch inventory precisely because nobody thinks of them as browsers, which is exactly what they are underneath.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions