Privilege Escalation in Firefox and Firefox ESR
CVE-2026-74965

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74965?

A vulnerability exists in the Shell Integration component of Firefox, enabling potential privilege escalation. This flaw affects multiple versions of Firefox and Firefox ESR, necessitating users to update to the latest releases—Firefox 154, Firefox ESR 140.14, or Firefox ESR 153.1—to mitigate risks and enhance security.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khanh Nguyen
.