Red Hat Security Advisory: firefox security update
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Incorrect boundary conditions in the Libraries component in NSS (CVE-2026-6772) * firefox: thunderbird: Use-after-free in the JavaScript Engine component (CVE-2026-6754) * firefox: thunderbird: Spoofing issue in the DOM: Core & HTML component (CVE-2026-6762) * firefox: thunderbird: Incorrect boundary conditions in the WebRTC component (CVE-2026-6752) * firefox: thunderbird: Other issue in the Storage: IndexedDB component (CVE-2026-6770) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-6757) * firefox: thunderbird: Other issue in the Libraries component in NSS (CVE-2026-6767) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (CVE-2026-6786) * firefox: thunderbird: Incorrect boundary conditions in the WebRTC component (CVE-2026-6753) * firefox: thunderbird: Use-after-free in the Widget: Cocoa component (CVE-2026-6759) * firefox: thunderbird: Use-after-free in the WebRTC component (CVE-2026-6747) * firefox: thunderbird: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component (CVE-2026-6749) * firefox: thunderbird: Incorrect boundary conditions in the Libraries component in NSS (CVE-2026-6766) * firefox: thunderbird: Privilege escalation in the Networking component (CVE-2026-6761) * firefox: thunderbird: Mitigation bypass in the File Handling component (CVE-2026-6763) * firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-6750) * firefox: thunderbird: Uninitialized memory in the Audio/Video: Web Codecs component (CVE-2026-6748) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (CVE-2026-6785) * firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-6771) * firefox: thunderbird: Incorrect boundary conditions in the DOM: Device Interfaces component (CVE-2026-6764) * firefox: thunderbird: Information disclosure in the Form Autofill component (CVE-2026-6765) * firefox: thunderbird: Privilege escalation in the Debugger component (CVE-2026-6769) * firefox: thunderbird: Uninitialized memory in the Audio/Video: Web Codecs component (CVE-2026-6751) * firefox: thunderbird: Incorrect boundary conditions in the WebRTC: Networking component (CVE-2026-6776) * firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-6746) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This Red Hat security advisory (RHSA-2026:10757) covers a comprehensive set of 25 vulnerabilities affecting Mozilla Firefox and Thunderbird, including CVE-2026-6746 and others. The issues include use-after-free vulnerabilities in the JavaScript engine, DOM, WebRTC, and Widget components; incorrect boundary conditions in NSS libraries, WebRTC, and DOM device interfaces; privilege escalation in networking, graphics, and debugger components; information disclosure from uninitialized memory in graphics and audio/video components; spoofing in DOM core and HTML; and mitigation bypasses in file handling and DOM security. These vulnerabilities are fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150, and Thunderbird 150 packages for Red Hat Enterprise Linux 9 and its variants. The advisory rates the update as important and provides detailed fixes for each CVE.
Potential Impact
The vulnerabilities collectively could allow attackers to execute arbitrary code, escalate privileges, cause information disclosure, or bypass security mitigations in affected Firefox and Thunderbird versions on Red Hat Enterprise Linux 9. The presence of use-after-free and memory safety bugs increases the risk of crashes or exploitation. Privilege escalation flaws could enable attackers to gain higher access rights. Information disclosure issues could leak sensitive data. Spoofing and mitigation bypass vulnerabilities could undermine security controls. However, no known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated Firefox and Thunderbird packages (including Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150, and Thunderbird 150) that address all listed vulnerabilities. Users and administrators should apply these official updates promptly to remediate the security issues. For detailed update instructions, refer to the Red Hat advisory at https://access.redhat.com/articles/11258. No additional mitigation actions are indicated beyond applying the provided patches.
Red Hat Security Advisory: firefox security update
Description
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Incorrect boundary conditions in the Libraries component in NSS (CVE-2026-6772) * firefox: thunderbird: Use-after-free in the JavaScript Engine component (CVE-2026-6754) * firefox: thunderbird: Spoofing issue in the DOM: Core & HTML component (CVE-2026-6762) * firefox: thunderbird: Incorrect boundary conditions in the WebRTC component (CVE-2026-6752) * firefox: thunderbird: Other issue in the Storage: IndexedDB component (CVE-2026-6770) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-6757) * firefox: thunderbird: Other issue in the Libraries component in NSS (CVE-2026-6767) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (CVE-2026-6786) * firefox: thunderbird: Incorrect boundary conditions in the WebRTC component (CVE-2026-6753) * firefox: thunderbird: Use-after-free in the Widget: Cocoa component (CVE-2026-6759) * firefox: thunderbird: Use-after-free in the WebRTC component (CVE-2026-6747) * firefox: thunderbird: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component (CVE-2026-6749) * firefox: thunderbird: Incorrect boundary conditions in the Libraries component in NSS (CVE-2026-6766) * firefox: thunderbird: Privilege escalation in the Networking component (CVE-2026-6761) * firefox: thunderbird: Mitigation bypass in the File Handling component (CVE-2026-6763) * firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-6750) * firefox: thunderbird: Uninitialized memory in the Audio/Video: Web Codecs component (CVE-2026-6748) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (CVE-2026-6785) * firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-6771) * firefox: thunderbird: Incorrect boundary conditions in the DOM: Device Interfaces component (CVE-2026-6764) * firefox: thunderbird: Information disclosure in the Form Autofill component (CVE-2026-6765) * firefox: thunderbird: Privilege escalation in the Debugger component (CVE-2026-6769) * firefox: thunderbird: Uninitialized memory in the Audio/Video: Web Codecs component (CVE-2026-6751) * firefox: thunderbird: Incorrect boundary conditions in the WebRTC: Networking component (CVE-2026-6776) * firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-6746) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
pkg:rpm/redhat/thunderbirdRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory (RHSA-2026:10757) covers a comprehensive set of 25 vulnerabilities affecting Mozilla Firefox and Thunderbird, including CVE-2026-6746 and others. The issues include use-after-free vulnerabilities in the JavaScript engine, DOM, WebRTC, and Widget components; incorrect boundary conditions in NSS libraries, WebRTC, and DOM device interfaces; privilege escalation in networking, graphics, and debugger components; information disclosure from uninitialized memory in graphics and audio/video components; spoofing in DOM core and HTML; and mitigation bypasses in file handling and DOM security. These vulnerabilities are fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150, and Thunderbird 150 packages for Red Hat Enterprise Linux 9 and its variants. The advisory rates the update as important and provides detailed fixes for each CVE.
Potential Impact
The vulnerabilities collectively could allow attackers to execute arbitrary code, escalate privileges, cause information disclosure, or bypass security mitigations in affected Firefox and Thunderbird versions on Red Hat Enterprise Linux 9. The presence of use-after-free and memory safety bugs increases the risk of crashes or exploitation. Privilege escalation flaws could enable attackers to gain higher access rights. Information disclosure issues could leak sensitive data. Spoofing and mitigation bypass vulnerabilities could undermine security controls. However, no known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated Firefox and Thunderbird packages (including Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150, and Thunderbird 150) that address all listed vulnerabilities. Users and administrators should apply these official updates promptly to remediate the security issues. For detailed update instructions, refer to the Red Hat advisory at https://access.redhat.com/articles/11258. No additional mitigation actions are indicated beyond applying the provided patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:10757
- Cve Count
- 25
- Additional Cves
- ["CVE-2026-6747","CVE-2026-6748","CVE-2026-6749","CVE-2026-6750","CVE-2026-6751","CVE-2026-6752","CVE-2026-6753","CVE-2026-6754","CVE-2026-6757","CVE-2026-6759","CVE-2026-6761","CVE-2026-6762","CVE-2026-6763","CVE-2026-6764","CVE-2026-6765","CVE-2026-6766","CVE-2026-6767","CVE-2026-6769","CVE-2026-6770","CVE-2026-6771","CVE-2026-6772","CVE-2026-6776","CVE-2026-6785","CVE-2026-6786"]
- Cvss Version
- null
Threat ID: 6a16095be29bf47b50624f1a
Added to database: 05/26/2026, 20:58:03 UTC
Last enriched: 06/28/2026, 00:53:27 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.