DSA-6451-1 firefox-esr - security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, privilege escalation, information disclosure or bypass of the same-origin policy. https://security-tracker.debian.org/tracker/DSA-6451-1
CSIRTS triage
- What
- Multiple security flaws in Firefox ESR allow arbitrary code execution, privilege escalation, information disclosure, and same-origin policy bypass.
- Who is affected
- Users of Firefox ESR on Debian systems.
- Urgency
- High; multiple critical vulnerabilities affecting core browser security controls warrant prompt patching.
- Action
- Update Firefox ESR to the patched version specified in DSA-6451-1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firefox ESR
Get an email when a new Firefox ESR advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00362.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-749340.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749350.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749360.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749390.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749400.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749410.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749420.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749430.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749440.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749450.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund
- unknownMozilla Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Mozilla products (August 19, 2026)cert-fr-avis
- criticalCVE-2026-74990: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird…nvd
- criticalCVE-2026-74987: Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird…nvd
- highCVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firef…nvd
- mediumCVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Fi…nvd
- mediumCVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in…nvd
- mediumCVE-2026-74973: Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Fire…nvd
- mediumCVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed …nvd
- mediumCVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability wa…nvd
- highCVE-2026-74969: Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefo…nvd
More from Debian Security Advisories
- unknownDSA-6448-1 spip - security update2026-08-18
- unknownDSA-6447-1 librabbitmq - security update2026-08-18
- unknownDSA-6450-1 srt - security update2026-08-18
- unknownDSA-6449-1 swift - security update2026-08-18
- highDSA-6446-1 expat - security update2026-08-18