Mozilla · Firefox · CVE-2026-12294
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 152
Firefox ESR versions prior to 140.12
Firefox ESR versions prior to 115.37
Thunderbird versions prior to 152
Thunderbird versions prior to 140.12
**Description**
A sandbox escape exists within the DOM: Workers component. A sandbox is a security mechanism for separating running programs, usually in an effort to mitigate system failures or software vulnerabilities from spreading.
**Recommendations**
Update Firefox to version 152.
Update Firefox ESR to version 140.12.
Update Firefox ESR to version 115.37.
Update Thunderbird to version 152.
Update Thunderbird to version 140.12.