Mozilla released security updates for Firefox 154, supported Firefox ESR branches, and Thunderbird to fix a broad set of vulnerabilities affecting desktop and mobile users. Government and vendor advisories said the updates address 3 critical and 17 high-severity flaws involving arbitrary code execution, privilege escalation, security restriction bypass, sandbox escape, site isolation failures, use-after-free conditions, and information disclosure. Firefox 154 also introduced product changes including expanded Local Access Network protections for WebSocket connections, while security notices from Canada and Italy urged organizations to review Mozilla bulletins and update affected installations.
Tenable and downstream Linux advisories flagged the issue set as critical across Windows, macOS, and Slackware packages, with affected versions including Firefox releases prior to 154, multiple ESR builds before their patched versions, and Thunderbird releases prior to 140.14 or 154.0 depending on branch. Nessus coverage tied the fixes to numerous CVEs, including CVE-2026-74990 as a scoring reference in several advisories, and highlighted specific Thunderbird issues such as a Remote Settings Client sandbox escape, a CanvasWebGL site isolation flaw, a DOM: Networking privilege escalation bug, and WebAssembly and garbage-collection use-after-free vulnerabilities. The recommended action across all notices was to upgrade Mozilla products to the latest patched versions immediately.

See affected versions and whether adversaries are exploiting it.
33 events from the most recent confirmed update back to the earliest known activity.
Tenable released Nessus plugin 339057 for Miracle Linux 9 to detect missing Thunderbird updates from advisory AXSA-2026-1625. The plugin says the patch was published on August 24, 2026, covers multiple Thunderbird vulnerabilities, and notes that exploits are available.
Tenable published Nessus plugin 339042 for Debian DSA-6461 covering the Thunderbird source package in Debian trixie. The entry links Debian security tracker records for numerous CVEs in the CVE-2026-74934 through CVE-2026-74990 range, indicating Debian-specific tracking of Thunderbird security updates.
Tenable released Nessus plugin 338826 for SUSE SLED15, SLED_SAP15, SLES15, and SLES_SAP15 systems to detect missing Firefox security updates from advisory SUSE-SU-2026:3658-1. The plugin covers Firefox ESR 140.14.0 ESR, ties the fixes to Mozilla vulnerabilities disclosed on August 18, 2026, and notes the SUSE patch publication date as August 20, 2026.
Tenable published Nessus plugin 338774 for Debian DLA-4750 to detect Firefox ESR security updates affecting Debian Linux 11 and 12, including numerous firefox-esr localization packages. The notice ties the Debian-packaged fixes to Mozilla vulnerabilities disclosed on August 18, 2026, and states patches were published on August 21, 2026 with no known exploits available.
Tenable released Nessus plugin 338684 to detect openSUSE 16 systems missing advisory openSUSE-SU-2026:21594-1 for Mozilla Firefox packages. The plugin covers Firefox Extended Support Release 140.14.0 ESR and maps the update to multiple critical vulnerabilities referenced in MFSA 2026-76.
The Canadian Centre for Cyber Security published advisory AV26-840 warning that Firefox, Firefox ESR, and Thunderbird were affected by multiple vulnerabilities as of August 18, 2026. The notice directed users and administrators to review Mozilla advisories and apply updates.
Slackware published security advisories SSA:2026-231-01 and SSA:2026-231-02 for Mozilla Firefox and Thunderbird packages on Slackware Linux, including version 15.0. The advisories aggregate numerous Mozilla CVEs and list patch publication on August 19, 2026.
Tenable published Nessus plugins 337888 and 337889 for Windows and macOS covering Thunderbird versions earlier than 154.0 under Mozilla advisory MFSA-2026-78. The plugins describe multiple critical flaws, including CVE-2026-75874, and recommend upgrading to Thunderbird 154.0 or later.
Tenable released Nessus plugins for Windows and macOS to detect Mozilla Thunderbird installations missing version 140.14 and affected by multiple vulnerabilities. The plugins state the patch and vulnerability publication dates were August 18, 2026.
Mozilla released security updates addressing multiple vulnerabilities across Firefox, Firefox ESR, and Thunderbird, including 3 critical and 17 high-severity flaws. Fixed versions include Firefox 154, Firefox ESR 115.39/140.14/153.1, and Thunderbird 154/153.1/140.14.
Tenable published a reference for Debian DLA-4754 covering Thunderbird source packages in Debian Bookworm and Bullseye. It links the update to 31 Debian Security Tracker CVEs, including CVE-2026-74934 through CVE-2026-74990 with non-contiguous identifiers.
Mozilla removed experimental JPEG-XL image-format support that had been planned for Firefox 157. The implementation had used the Rust-based jxl-rs library.
Mozilla released Firefox 154.0.1 to address multiple security issues, including a buffer-overflow flaw, HTTP request-processing issues, and Windows-specific font-handling behavior involving MS UI Gothic. Some of the flaws could cause browser crashes or unintended behavior when maliciously crafted content is processed.
Red Hat disclosed that CVE-2026-74943, a use-after-free vulnerability in Firefox's Graphics: ImageLib component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74957, a mitigation bypass vulnerability in Firefox's Safe Browsing component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74953, a privilege escalation vulnerability in Firefox's Networking: Cookies component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74967, a same-origin policy bypass in Firefox's Audio/Video: Playback component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74987 covered internally found bugs in Firefox ESR 140.13, Firefox ESR 153.0, and Firefox 153, with some showing evidence of memory corruption or another security-relevant defect and potential exploitability. Red Hat said the issue was fixed upstream in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1, and addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74976, a JIT miscompilation vulnerability in Firefox's JavaScript Engine: JIT component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74941, a privilege escalation vulnerability in Firefox's Graphics: CanvasWebGL component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74972, an information disclosure vulnerability in Firefox's DOM Push Subscriptions component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74974, a same-origin policy bypass vulnerability in Firefox's Graphics: ImageLib component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74969, a use-after-free vulnerability in Firefox's Layout: Text and Fonts component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74948, an information disclosure vulnerability in Firefox's Graphics component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74945, an information disclosure flaw in Firefox's Graphics: Text component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74963, a same-origin policy bypass flaw in Firefox's Networking: Cookies component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74935, a privilege escalation flaw in Firefox's DOM Networking component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74934, a site isolation issue in Firefox's Graphics: CanvasWebGL component, was fixed upstream in Firefox 154 and Firefox ESR 115.39/140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74949, a privilege-escalation vulnerability caused by a use-after-free flaw in Firefox's Graphics: Canvas2D component, was fixed upstream in Firefox 154 and Firefox ESR 140.14/153.1. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74939, a privilege escalation flaw in Firefox's DOM Navigation component, was fixed upstream in Firefox 154 and supported ESR releases. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat disclosed that CVE-2026-74973, a race condition and use-after-free flaw in Firefox's Graphics component, was fixed upstream in Firefox 154 and supported ESR releases. Red Hat said the issue was also addressed for Red Hat Enterprise Linux 8, 9, and 10 through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Red Hat addressed CVE-2026-74959, a mitigation bypass in Firefox's Storage: Cache API component, in Red Hat Enterprise Linux 8, 9, and 10. The fixes were published through advisories RHSA-2026:58898, RHSA-2026:58897, and RHSA-2026:58899.
Mozilla released Firefox 154, introducing functional and security-relevant changes including Local Access Network protections extended to WebSocket connections, a new "Manage AI" quick action, and other browser and developer updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
48 references tracked. Mallory keeps watching after this page renders.
opennet.me
Open sourceopennet.ru
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcephoronix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.