Mozilla Product Security Update Advisory

Mozilla Product Security Update Advisory

Overview

Mozilla has released security updates to address vulnerabilities discovered in Firefox, Firefox ESR, and Thunderbird. Affected products should be updated to the latest version.

Affected Products and Versions

  • Firefox: Versions earlier than 154.
  • Firefox ESR: Versions prior to 115.39, 140.14, And 153.1.
  • Thunderbird: Versions prior to 154, 140.14, And 153.1.

Key Vulnerabilities

  • CVE-2026-74935. A privilege escalation vulnerability in the DOM: Networking component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74937. Use-after-free vulnerability in the JavaScript: GC component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74938. Security mitigation bypass vulnerability in the JavaScript: GC component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74939. Firefox, Firefox ESR, and Thunderbird DOM: Privilege escalation vulnerability in the Navigation component.
  • CVE-2026-74941. Firefox, Firefox ESR, and Thunderbird Graphics: Privilege escalation vulnerability in the CanvasWebGL component.
  • CVE-2026-74942. A privilege escalation vulnerability in the Remote Settings Client component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74946. A privilege escalation vulnerability in the Graphics: CanvasWebGL component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74947. A privilege escalation vulnerability in the Graphics component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74949. A privilege escalation vulnerability in the Graphics: Canvas2D component of Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-74990. Vulnerabilities caused by memory corruption and other security-related defects discovered in Firefox, Firefox ESR, and Thunderbird.
  • CVE-2026-75874. A sandbox escape vulnerability in the Remote Settings Client component of Firefox and Thunderbird.

Action

Vulnerability Patches have been provided via the latest updates. Users should update to the latest version with Vulnerability Patches following the instructions on the reference sites.

Reference

Security advisories from Mozilla Foundation Security Advisory 2026-74 through 2026-80 have been issued.