Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196739 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-8401PATCHED
mozilla · firefox

Sandbox escape in the Profile Backup component

Description

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

Affected Products

VendorProductVersions
mozillafirefox—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mozillathunderbirdcert_advisory90%
mozillafirefox esrcert_advisory90%
mozillafirefoxcert_advisory90%
oraclesolariscert_advisory90%

References

  • https://bugzilla.mozilla.org/show_bug.cgi?id=2038679
  • https://www.mozilla.org/security/advisories/mfsa2026-45/
  • https://www.mozilla.org/security/advisories/mfsa2026-47/
  • https://www.mozilla.org/security/advisories/mfsa2026-48/
  • https://www.mozilla.org/security/advisories/mfsa2026-51/

Related News (8 articles)

Tier B
BSI Advisories33d ago
[NEU] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CCCS Canada83d ago
Mozilla security advisory (AV26-542)
→ No new info (linked only)
Tier B
BSI Advisories96d ago
[NEU] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR97d ago
Multiples vulnérabilités dans les produits Mozilla (20 mai 2026)
→ No new info (linked only)
Tier B
BSI Advisories103d ago
[NEU] [hoch] Mozilla Firefox: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR104d ago
Multiples vulnérabilités dans Mozilla Firefox (13 mai 2026)
→ No new info (linked only)
Tier B
CCCS Canada104d ago
Mozilla security advisory (AV26-451)
→ No new info (linked only)
Tier C
VulDB104d ago
CVE-2026-8401 | Mozilla Firefox up to 150.0.2 Profile Backup sandbox
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
151.0.3
PublishedMay 12, 2026
Last enriched83d agov3
Tags
security advisoryupdate
Trending Score2
Source articles8
Independent4
Info Completeness8/14
Missing: epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-74989EXP
Internally found bugs fixed in Firefox 154
Trending: 34
CRITICALCVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Trending: 32
CRITICALCVE-2026-74961
Side-channel in the Web Audio component
Trending: 32
CRITICALCVE-2026-74940
Use-after-free in the Graphics: Text component
Trending: 32
CRITICALCVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 12, 2026
Discovered by ZDM
May 12, 2026
Updated: description, affectedVersions, severity
May 12, 2026
Updated: affectedVersions, patchAvailable
Jun 2, 2026
Patch Available
Jul 15, 2026

Version History

v3
Last enriched 83d ago
v3Tier B83d ago

Added affected version 151.0.3 and updated patch availability to 151.0.3.

affectedVersionspatchAvailable
via CCCS Canada
v2Tier C104d ago

Updated description with new details, marked severity as CRITICAL, and added affected version 150.0.2.

descriptionaffectedVersionsseverity
via VulDB
v1104d ago

Initial creation