CVE-2026-0888: Mozilla Firefox
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
Affected products
Published 2026-01-13. Last modified 2026-06-17.