{"id":"RHSA-2026:58899","summary":"Red Hat Security Advisory: firefox security update","modified":"2026-08-27T10:15:33Z","published":"2026-08-25T10:23:00Z","upstream":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74948","CVE-2026-74949","CVE-2026-74953","CVE-2026-74957","CVE-2026-74959","CVE-2026-74960","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74967","CVE-2026-74969","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74983","CVE-2026-74987","CVE-2026-74990"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:58899"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517819"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517820"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517822"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517823"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517825"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517826"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517831"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517833"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517834"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517835"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517836"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517837"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517839"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517840"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517841"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517845"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517846"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517849"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517851"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517853"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517856"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517858"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517859"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517860"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517862"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517863"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517866"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517868"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517870"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517872"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517874"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_58899.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74934"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74934"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74934"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74934"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74934"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74935"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74935"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74935"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74935"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74935"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74936"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74936"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74936"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74936"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74936"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74939"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74939"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74939"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74939"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74939"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74940"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74940"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74940"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74940"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74940"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74941"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74941"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74941"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74941"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74941"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74942"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74942"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74942"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74942"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74942"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74943"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74943"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74943"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74943"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74943"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74944"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74944"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74944"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74944"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74944"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74945"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74945"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74945"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74945"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74945"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74946"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74946"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74946"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74946"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74946"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74948"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74948"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74948"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74948"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74948"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74949"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74949"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74949"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74949"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74949"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74953"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74953"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74953"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74953"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74953"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74957"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74957"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74957"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74957"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74957"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74959"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74959"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74959"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74959"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74959"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74960"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74960"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74960"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74960"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74960"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74962"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74962"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74962"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74962"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74962"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74963"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74963"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74963"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74963"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74963"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74964"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74964"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74964"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74964"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74964"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74965"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74965"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74965"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74965"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74965"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74967"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74967"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74967"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74967"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74967"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74969"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74969"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74969"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74969"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74969"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74971"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74971"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74971"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74971"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74971"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74972"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74972"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74972"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74972"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74972"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74973"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74973"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74973"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74973"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74973"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74974"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74974"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74974"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74974"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74974"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74976"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74976"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74976"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74976"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74976"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74983"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74983"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74983"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74983"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74983"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74987"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74987"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74987"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74987"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74987"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-74990"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-74990"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74990"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-76/#CVE-2026-74990"},{"type":"ARTICLE","url":"https://www.mozilla.org/security/advisories/mfsa2026-79/#CVE-2026-74990"}],"affected":[{"package":{"name":"firefox","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/firefox"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:140.14.0-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:58899.json"}},{"package":{"name":"firefox-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/firefox-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:140.14.0-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:58899.json"}},{"package":{"name":"firefox-debugsource","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/firefox-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:140.14.0-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:58899.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}