Firefox ESR 115
is now supported only on Windows 7-8.1 and macOS 10.12-10.14. Users on
other operating systems should use Firefox ESR 140 instead.
Mozilla Foundation Security Advisory 2026-75
Security Vulnerabilities fixed in Firefox ESR 115.39
Announced
August 18, 2026Impact
highProducts
Firefox ESRFixed in
Firefox ESR 115.39
#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
Reporter
satyamasdImpact
high
References
Bug 2050584
#CVE-2026-74935: Privilege escalation in the DOM: Networking component
Reporter
Yaqoub AldurayhimImpact
high
References
Bug 2051013
#CVE-2026-74939: Privilege escalation in the DOM: Navigation component
Reporter
choeseyeongImpact
high
References
Bug 2054416
#CVE-2026-74940: Use-after-free in the Graphics: Text component
Reporter
kiyongImpact
high
References
Bug 2054842
#CVE-2026-74942: Privilege escalation in the Remote Settings Client component
Reporter
Gal AnkoninaImpact
high
References
Bug 2056571
#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
Reporter
Abdulaziz AlasaiqahImpact
high
References
Bug 2057308
#CVE-2026-74945: Information disclosure in the Graphics: Text component
Reporter
Abdulaziz AlasaiqahImpact
high
References
Bug 2057808
#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Reporter
locust1bImpact
high
References
Bug 2059997
#CVE-2026-74948: Information disclosure in the Graphics component
Reporter
Yaqoub AldurayhimImpact
high
References
Bug 2060106
#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
Reporter
Hyeonjun AhnImpact
moderate
References
Bug 2056065
#CVE-2026-74973: Race condition, use-after-free in the Graphics component
Reporter
r00tdaddyImpact
moderate
References
Bug 2060357
#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
Reporter
The Mozilla Fuzzing TeamImpact
moderate
References
Bug 2061794
#CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Reporter
Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing TeamImpact
high
Description
Internally found bugs present in Firefox ESR 115.38, Firefox ESR
140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed
evidence of memory corruption or another security-relevant defect and we
presume that with enough effort some of these could have been
exploited.
References
High Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Moderate Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154