ISN 2026-30: Critical Firefox ESR Vulnerabilities

First published 22 July 2026

Critical

(No vector available)

Summary

Multiple security vulnerabilities have been found in Firefox ESR, a web browser used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

Mozilla reports two vulnerabilities in Firefox ESR that it rates as critical: An invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) and a site isolation issue in DOM: Navigation (CVE-2026-15719). Exploit code for these is publicly available, but the Mozilla Foundation state they are not aware of attacks in the wild. Other organizations, such as CISA-ADP, rate these issues lower.

In addition, 16 vulnerabilities rated high have been discovered, among them a same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349), a sandbox escape due to use-after-free in DOM: Navigation (CVE-2026-16351), and an Integer overflow in JavaScript: WebAssembly (CVE-2026-16369). The full list is available in the Mozilla Foundation Security Advisory (MFSA) referenced.

Update Instructions

  • OS 12: Upgrade the Firefox ESR app to version 140.13 as soon as it is available on the IGEL App Portal.

  • OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.

References