CVE-2026-74952
EUVD-2026-6068018.08.2026, 13:17
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mozilla | firefox | 𝑥 < 154.0.0 | CNA |
| mozilla | thunderbird | 𝑥 < 154.0 | CNA |
| mozilla | firefox_esr | 141.0.0 ≤ 𝑥 < 153.2 | CNA |
| mozilla | thunderbird_esr | 141.0.0 ≤ 𝑥 < 153.2 | CNA |
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||
| thunderbird |
| ||||||||||
| mozjs38 |
| ||||||||||
| mozjs52 |
| ||||||||||
| mozjs68 |
| ||||||||||
| mozjs78 |
| ||||||||||
| mozjs91 |
| ||||||||||
| mozjs102 |
| ||||||||||
| mozjs115 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MozillaFirefox |
| ||||||||||||||||||||||||
| MozillaFirefox-branding-SLE-153 |
| ||||||||||||||||||||||||
| MozillaFirefox-devel |
| ||||||||||||||||||||||||
| MozillaFirefox-translations-common |
| ||||||||||||||||||||||||
| MozillaFirefox-translations-other |
|
Common Weakness Enumeration
Vulnerability Media Exposure