Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-75874: Firefox: Unprivileged Code Execution in Remote Settings
CVE-2026-75874 · published 16 days ago
Summary
The Firefox Remote Settings Client component allows unauthorized code to run with elevated privileges, potentially allowing an attacker to execute malicious code. This issue affects Firefox users who have enabled Remote Settings. To protect against this issue, update to the latest version of Firefox.
What to do
- Update mozilla firefox to version 154.0.0 or later.
- Update mozilla thunderbird to version 154.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:18.04:LTS | canonical | mozjs52 | All versions |
| Ubuntu:18.04:LTS | canonical | mozjs38 | All versions |
| Ubuntu:20.04:LTS | canonical | mozjs68 | All versions |
| Ubuntu:20.04:LTS | canonical | mozjs52 | All versions |
| Ubuntu:22.04:LTS | canonical | mozjs102 | All versions |
| Ubuntu:22.04:LTS | canonical | mozjs78 | All versions |
| – | mozilla | firefox | < 154.0.0 |
| – | mozilla | thunderbird | < 154.0 |
| Ubuntu:22.04:LTS | canonical | mozjs91 | All versions |
| Ubuntu:22.04:LTS | canonical | thunderbird | All versions |
| Ubuntu:24.04:LTS | canonical | mozjs102 | All versions |
| Ubuntu:24.04:LTS | canonical | mozjs115 | All versions |
| Debian:12 | debian | firefox-esr | All versions |
| Debian:13 | debian | firefox-esr | All versions |
| Debian:14 | debian | firefox-esr | All versions |
Original advisory text
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2039972
- https://www.mozilla.org/security/advisories/mfsa2026-74/
- https://www.mozilla.org/security/advisories/mfsa2026-78/
- https://www.cve.org/CVERecord?id=CVE-2026-75874 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-75874 Third Party Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874 Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-83/
- https://www.mozilla.org/security/advisories/mfsa2026-84/
- https://www.mozilla.org/security/advisories/mfsa2026-85/
- https://security-tracker.debian.org/tracker/CVE-2026-75874 Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-87/
- https://www.mozilla.org/security/advisories/mfsa2026-88/
Severity
10.0
Critical
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-693Protection Mechanism Failure
Timeline
Published18 Aug 2026
Updated2 Sep 2026
First seen18 Aug 2026
Sources
UBUNTU-CVE-2026-75874 · OSV
CVE-2026-75874 · NVD
CVE-2026-75874 · MITRE
DEBIAN-CVE-2026-75874 · OSV
Monitor software like this
Free during beta