Security update for MozillaFirefox
Description
This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.14.0 ESR. - MFSA 2026-76 (bsc#1274867) * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics:Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers a broad set of security vulnerabilities in Mozilla Thunderbird and Firefox components as packaged in Red Hat Enterprise Linux. The issues include use-after-free bugs (e.g., in Graphics: ImageLib, Canvas2D, JavaScript WebAssembly), privilege escalation flaws (e.g., in Graphics CanvasWebGL, Shell Integration, DOM Navigation), information disclosure vulnerabilities (e.g., in Graphics Text, DOM UI Events), site isolation issues (e.g., Graphics CanvasWebGL, Networking Cookies), and mitigation bypasses (e.g., Data Loss Prevention, Safe Browsing). These bugs were internally found and fixed in Firefox ESR 140.14, ESR 153.1, and Firefox 154. Red Hat has issued security updates for affected RHEL 9 and 10 AppStream and Extended Update Support versions, addressing these vulnerabilities. The vendor advisory confirms the availability of patches and provides detailed bug references and impact ratings.
Potential Impact
The vulnerabilities collectively pose a high security risk, including potential privilege escalation, information disclosure, and bypass of security mitigations. Exploitation could allow attackers to escalate privileges, access sensitive information, or bypass security boundaries within the affected Thunderbird and Firefox components. However, there are no known exploits in the wild at this time. The issues affect multiple critical components such as graphics rendering, networking, DOM handling, and JavaScript execution, increasing the potential attack surface.
Mitigation Recommendations
Red Hat has released official security updates addressing these vulnerabilities in Firefox ESR 140.14 and related versions for Red Hat Enterprise Linux 9 and 10. Users should apply the provided patches promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. Since this is an official fix, applying the update fully mitigates the described vulnerabilities. No additional mitigation steps are required beyond applying the vendor-supplied patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:58899
- Cve Count
- 31
- Additional Cves
- ["CVE-2026-74935","CVE-2026-74936","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74948","CVE-2026-74949","CVE-2026-74953","CVE-2026-74957","CVE-2026-74959","CVE-2026-74960","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74967","CVE-2026-74969","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74983","CVE-2026-74987","CVE-2026-74990"]
- State
- PUBLISHED
Threat ID: 6a8c4c48acd9273b499be014
Added to database: 08/24/2026, 13:51:04 UTC
Last enriched: 09/09/2026, 14:46:13 UTC
Last updated: 10/08/2026, 06:48:19 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.