Red Hat released Important Firefox security updates for Red Hat Enterprise Linux 8, 9, and 10, updating the browser to the 140.14.0 package stream across standard, extended support, and lifecycle variants on x86_64, s390x, ppc64le, and aarch64. The advisories say the updates remediate 31 Mozilla Firefox vulnerabilities spanning privilege escalation, use-after-free, information disclosure, same-origin policy bypass, site isolation flaws, mitigation bypasses, integer overflow, and JIT miscompilation issues.
The fixed issues include CVEs in the CVE-2026-74934 to CVE-2026-74990 range, with examples such as CVE-2026-74983, CVE-2026-74953, CVE-2026-74976, and CVE-2026-74990. Red Hat said affected components include CanvasWebGL, Cookies, Graphics, WebAssembly, WebExtensions, DOM, Safe Browsing, and Remote Settings Client, while related downstream tracking appeared in Rocky Linux through RLSA-2026:58898, indicating corresponding ecosystem patching for Firefox on enterprise Linux platforms.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
AlmaLinux published ALSA-2026:58897 for Firefox and Firefox-X11 on AlmaLinux 9 across its supported repositories. The update addresses 31 Firefox CVEs, including CVE-2026-74944, and the notice states that exploits are available.
AlmaLinux published ALSA-2026:58899 for Firefox on AlmaLinux 10 across multiple repositories and deployment variants. The update addresses 31 CVEs, and the notice states that exploits are available.
Red Hat published Important advisory RHSA-2026:58899, providing Firefox 140.14.0-1.el10_2 for RHEL 10 and RHEL 10.2 support streams. The update addresses 31 Mozilla Firefox vulnerabilities, including privilege escalation, use-after-free, information disclosure, site-isolation, and JIT-miscompilation flaws.
Red Hat published Important advisory RHSA-2026:58897, providing Firefox 140.14.0-1.el9_8 for RHEL 9, including EUS, SAP, four-year update, and Extended Life Cycle streams. It fixes 31 Firefox vulnerabilities, including CVE-2026-74983, CVE-2026-74934, CVE-2026-74953, and CVE-2026-74976.
Red Hat published Important advisory RHSA-2026:58898, delivering Firefox 140.14.0-1.el8_10 for RHEL 8 and RHEL 8.10 Extended Life Cycle variants. The update remediates numerous Firefox flaws including privilege-escalation, use-after-free, site-isolation, mitigation-bypass, and same-origin-policy issues.
SUSE advisory SUSE-SU-2026:3683-1 updated Mozilla Firefox packages on SUSE Linux Enterprise Server 12 to Firefox ESR 140.14.0. The update addresses CVE-2026-74934 through CVE-2026-74990 and CVE-2026-75874, including use-after-free, privilege-escalation, sandbox-escape, and JIT-miscompilation flaws.
Red Hat published Moderate advisory RHSA-2026:49851 for kernel-rt on RHEL 8, fixing CVE-2026-52923, a kernel IPC next_id allocation issue. The update also included KVM s390 and CIFS mount bug fixes and requires affected systems to be rebooted.
A Tenable Nessus plugin linked Rocky Linux security errata RLSA-2026:58898 with multiple related Red Hat Bugzilla tickets. The reference did not provide vulnerability, package, impact, or remediation details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.