Mozilla Firefox ↗
Summary iPlain-English security verdict for Mozilla Firefox, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.
Mozilla Firefox currently scores 100/100 — healthy. 3 actively-exploited vulnerabilities (CISA KEV) affect older releases (e.g. CVE-2024-9680) — staying on the latest supported version keeps you clear of them. The latest supported release is 155.0. It's on the latest patch with no significant known issues — keep it current.
Disclosure trend iNew CVEs published for Mozilla Firefox each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.
1 of its known vulnerability is linked to ransomware campaigns (CISA KEV).
Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.
Most urgent first — actively exploited, then likeliest to be exploited.
CVE-2024-9680 CRITICAL exploited ransomware Use-after-free EPSS 23% → fixed in 131.0.2 CVE-2022-26485 HIGH exploited Use-after-free EPSS 14% → fixed in 97.3.0 CVE-2022-26486 CRITICAL exploited Use-after-free EPSS 2% → fixed in 97.3.0 CVE-2026-4698 CRITICAL CWE-843 EPSS 1% → fixed in 149.0 CVE-2026-4689 CRITICAL Integer overflow EPSS 1% → fixed in 149.0 CVE-2026-2796 CRITICAL CWE-843 EPSS 1% → fixed in 148.0 CVE-2026-74943 CRITICAL Use-after-free EPSS 1% → fixed in 153.1.0 CVE-2026-2773 CRITICAL Memory corruption EPSS 1% → fixed in 148.0 CVE-2026-2775 CRITICAL CWE-288 EPSS 1% → fixed in 148.0 CVE-2026-2762 CRITICAL Integer overflow EPSS 1% → fixed in 148.0 CVE-2026-2774 CRITICAL Integer overflow EPSS 1% → fixed in 148.0 CVE-2026-74990 CRITICAL Memory corruption EPSS 1% → fixed in 153.1.0Get alerted about Mozilla Firefox
Be emailed the moment Mozilla Firefox gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.
We email only on real events for Mozilla Firefox — no marketing, no sharing, and we never know what you run. Track your whole stack →
Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.
How long each Mozilla Firefox release line is supported — and when it sunsets. Select a line for its full report.
Full Mozilla Firefox end-of-life dates & support timeline →
155 latest 155.0 Supported 155.0 → 154 latest 154.0.1 End of life ended 2026-09-01154.0.1 → 153 latest 153.2.0 Supported 153.2.0 → 152 latest 152.0.6 End of life ended 2026-07-21152.0.6 → 151 latest 151.0.4 End of life ended 2026-06-16151.0.4 → 150 latest 150.0.3 End of life ended 2026-05-18150.0.3 → 149 latest 149.0.2 End of life ended 2026-04-21149.0.2 → 148 latest 148.0.2 End of life ended 2026-03-24148.0.2 → 147 latest 147.0.4 End of life ended 2026-02-24147.0.4 → 146 latest 146.0.1 End of life ended 2026-01-13146.0.1 → See all upcoming end-of-life dates →Frequently asked
Is Mozilla Firefox safe and patched?
Mozilla Firefox currently scores 100/100 — healthy. 3 actively-exploited vulnerabilities (CISA KEV) affect older releases (e.g. CVE-2024-9680) — staying on the latest supported version keeps you clear of them. The latest supported release is 155.0. It's on the latest patch with no significant known issues — keep it current.
What should I do about Mozilla Firefox now?
Upgrade Mozilla Firefox to the latest supported release (155.0) or later, which clears the actively-exploited issues affecting older versions, then confirm against Mozilla's official advisory.
When does Mozilla Firefox reach end-of-life?
The latest supported Mozilla Firefox release is 155.0. After end-of-life a release no longer receives security patches.
Which versions of Mozilla Firefox are still receiving security updates?
Supported Mozilla Firefox release lines (latest 155.0): 155, 153, 140, 115. End-of-life releases no longer receive security patches.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Mozilla's official advisory before you patch or upgrade — Mozilla Firefox official site ↗