DSA-6481-1 firefox-esr - security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or privilege escalation. https://security-tracker.debian.org/tracker/DSA-6481-1
CSIRTS triage
- What
- Multiple security issues including arbitrary code execution, sandbox escape, and privilege escalation in Firefox.
- Who is affected
- All Firefox ESR users; severity and exploitability vary by CVE but span the full browser attack surface.
- Urgency
- Critical urgency due to potential remote code execution and sandbox escape; update immediately.
- Action
- Update Firefox ESR to the patched version specified in DSA-6481-1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firefox
Get an email when a new Firefox advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00392.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-163650.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-163710.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-758740.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841190.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841200.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841210.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841220.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841240.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841310.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-841430.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16365 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16371 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75874 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84119 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84120 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84121 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84122 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84124 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84131 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84143 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84145 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Mozilla Firefox and Thunderbird: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilitiescert-bund
- unknownMozilla Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Mozilla products (02 September 2026)cert-fr-avis
- highCVE-2026-84145: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 14…nvd
- unknownCVE-2026-84143: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 14…nvd
- highCVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was …nvd
- mediumCVE-2026-84124: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155,…nvd
- mediumCVE-2026-84122: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Fire…nvd
- criticalCVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fi…nvd
- mediumCVE-2026-84120: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Fire…nvd
More from Debian Security Advisories
- unknownDSA-6480-1 keystone - security update2026-09-01
- unknownDSA-6478-1 starlette - security update2026-08-30
- unknownDSA-6479-1 roundcube - security update2026-08-30
- unknownDSA-6477-1 linux - security update2026-08-29
- unknownDSA-6474-1 cockpit - security update2026-08-27