CVE-2026-8966: Information disclosure in the IP Protection component
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151 - Upgrade
Upgrade
Mozilla Firefox/IP Protectionto a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Mozilla Thunderbird/IP Protectionto a version that resolves this vulnerability.Fixed in 151
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-8945
- CVE-2026-8946
- CVE-2026-8947
- CVE-2026-8948
- CVE-2026-8949
- CVE-2026-8950
- CVE-2026-8951
- CVE-2026-8952
- CVE-2026-8953
- CVE-2026-8954
- CVE-2026-8955
- CVE-2026-8956
- CVE-2026-8957
- CVE-2026-8958
- CVE-2026-8959
- CVE-2026-8960
- CVE-2026-8961
- CVE-2026-8962
- CVE-2026-8963
- CVE-2026-8964
- CVE-2026-8965
- CVE-2026-8966
- CVE-2026-8967
- CVE-2026-8968
- CVE-2026-8969
- CVE-2026-8970
- CVE-2026-8971
- CVE-2026-8972
- CVE-2026-8973
- CVE-2026-8974
- CVE-2026-8975
Frequently Asked Questions
What is the severity of CVE-2026-8966?
CVE-2026-8966 has been classified as a moderate severity vulnerability.
How do I fix CVE-2026-8966?
To fix CVE-2026-8966, update your Mozilla Firefox or Thunderbird to version 151 or later.
What causes CVE-2026-8966?
CVE-2026-8966 is caused by an information disclosure vulnerability in the IP Protection component.
Which software is affected by CVE-2026-8966?
CVE-2026-8966 affects versions of Mozilla Firefox and Thunderbird prior to version 151.
Is CVE-2026-8966 still a risk if I'm using version 151?
No, if you are using version 151 or later of Mozilla Firefox or Thunderbird, you are not at risk from CVE-2026-8966.