RHSA-2026:67133HighCVSS 7.5

Red Hat Security Advisory: firefox security update

Published
September 14, 2026
Last Modified
September 27, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-16365 — firefox: thunderbird: Privilege escalation in the DOM: Workers component CVE-2026-75874 — firefox: thunderbird: Sandbox escape in the Remote Settings Client component CVE-2026-84119 — firefox: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-84120 — firefox: Use-after-free in the Audio/Video component CVE-2026-84121 — firefox: Sandbox escape due to use-after-free in the DOM: Security component CVE-2026-84122 — firefox: Use-after-free in the Audio/Video component CVE-2026-84124 — firefox: Use-after-free in the DOM: Core & HTML component CVE-2026-84131 — firefox: Privilege escalation due to invalid pointer in the Graphics component CVE-2026-84143 — firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 CVE-2026-84145 — firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40

🎯 Affected products18

  • Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-0:140.15.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-0:140.15.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-0:140.15.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-0:140.15.0-1.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-0:140.15.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debuginfo-0:140.15.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debuginfo-0:140.15.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debuginfo-0:140.15.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debuginfo-0:140.15.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debugsource-0:140.15.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debugsource-0:140.15.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debugsource-0:140.15.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-debugsource-0:140.15.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-x11-0:140.15.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-x11-0:140.15.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-x11-0:140.15.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • firefox-x11-0:140.15.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (12)