ISN 2026-33: Critical Firefox ESR Vulnerabilities

First published 2 September 2026 (Pre-Notification)

CVSS:3.1: 9.8 (Critical)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Summary

Multiple security vulnerabilities have been found in Firefox ESR, a web browser used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

Mozilla reports a use-after free in the JavaScript: WebAssembly component in Firefox (CVE-2026-74936). While Mozilla rates the severity as high, CISA-ADP classifies it as critical. A use-after-free in in the Graphics: Text component (CVE-2026-74940) is rated as critical by NVD.

Graphics: CanvasWebGL is affected by privilege escalation due to incorrect boundary conditions (CVE-2026-74946, high). Further privilege escalations have been discovered in DOM: Networking (CVE-2026-74935, high), DOM: Navigation (CVE-2026-74939, high), Graphics: CanvasWebGL (CVE-2026-74941, high), and in the Remote Settings Client (CVE-2026-74942, high).

Consult the referenced MFSA for a full list.

Update Instructions

  • OS 12: Upgrade the Firefox ESR app to version 140.14 or newer as soon as it is available on the IGEL APP Portal.

  • OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.

References