CVE-2026-12294Patch(mozilla / firefox)

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-07-05)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-25: 1Mentions · 2026-07-05: 2Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-05: 2Technical Details · 2026-06-25: 1Technical Details · 2026-07-05: 206-2507-05
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-251
Patch1
2026-07-052
Patch2
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:33445 – Thunderbird 140.12.0-1.el8_10 liberado para Rocky Linux 8. Corrige 15+ CVEs, incluindo CVE-2026-12289 (escalação de privilégio) e CVE-2026-12294 (sandbox escape). Saiba mais: -> http://tinyurl.com/4hjszp5x https://t.co/9YM2aUNCVx

    Post summary

    The post announces a new Thunderbird update for Rocky Linux 8 that patches several CVEs, including those for privilege escalation and sandbox escape, and provides links for additional details.

    10000118
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:33445 – Thunderbird 140.12.0-1.el8_10 liberado para Rocky Linux 8. Corrige 15+ CVEs, incluindo CVE-2026-12289 (escalação de privilégio) e CVE-2026-12294 (sandbox escape). Saiba mais: -> http://tinyurl.com/4hjszp5x https://t.co/ZAdXuigaCt

    Post summary

    The post announces the release of Thunderbird 140.12.0-1.el8_10 for Rocky Linux 8, highlighting that it resolves over 15 CVEs, including privilege escalation and sandbox escape issues.

    10000107
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    RLSA-2026-27717: Firefox 140.12.0 corrige 30+ CVEs críticos no Rocky Linux 8, incluindo RCE (CVE-2026-12289/12291), sandbox escape (CVE-2026-12294/12295) e memory safety bugs. Saiba mais: -> http://tinyurl.com/4ry83bep #RockyLinux #Firefox https://t.co/MESi906b3p

    Post summary

    The tweet announces that Firefox 140.12.0 on Rocky Linux 8 fixes over 30 critical CVEs—including RCE, sandbox escape, and memory safety bugs—highlighting the availability of a patch.

    1000066
    1.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more