Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Firefox: Code Execution via Malicious Add-Ons

RHSA-2026:3976
Summary

Firefox users are vulnerable to a security issue that can allow attackers to execute malicious code on a user's system. This issue affects Firefox's handling of add-ons, and users should update to the latest version to prevent potential attacks. The update fixes the vulnerability and adds new security features.

What to do
  • Update redhat firefox to version 0:140.8.0-2.el10_0.
  • Update redhat firefox-debuginfo to version 0:140.8.0-2.el10_0.
  • Update redhat firefox-debugsource to version 0:140.8.0-2.el10_0.
Affected software
VendorProductAffected versionsFix available
redhat firefox <= 0:140.8.0-2.el10_0 0:140.8.0-2.el10_0
redhat firefox-debuginfo <= 0:140.8.0-2.el10_0 0:140.8.0-2.el10_0
redhat firefox-debugsource <= 0:140.8.0-2.el10_0 0:140.8.0-2.el10_0
Original title
Red Hat Security Advisory: firefox security update
osv CVSS3.1 7.5
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026