Critical Firefox Vulnerabilities in Oracle Linux Prompt Urgent Updates

Critical Firefox Vulnerabilities in Oracle Linux Prompt Urgent Updates

First seen 26 Aug 2026, 12:22 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Oracle has released important security updates for Firefox in Oracle Linux 8, 9, and 10 due to multiple critical vulnerabilities. These updates address buffer overflow vulnerabilities and other security issues, with CVEs such as CVE-2026-74939 being publicly disclosed on August 25, 2026. The vulnerabilities affect various versions of Firefox across different Oracle Linux distributions, including 8, 9, and 10. Administrators are urged to apply the updates immediately to mitigate potential exploitation. The updates include patches for debranding and default preferences, as well as fixes for specific bugs. Affected systems include x86_64 and aarch64 architectures. The vulnerabilities have been linked to a range of CVEs, all published on August 18, 2026, indicating a significant security risk. The current status emphasizes the need for immediate action to secure systems against potential threats.

Key Points: • Critical vulnerabilities in Firefox for Oracle Linux require immediate updates. • Multiple CVEs, including CVE-2026-74939, pose significant risks to affected systems. • Updates are available for Oracle Linux 8, 9, and 10 across various architectures.

Timeline

2026-08-18
Multiple CVEs published
A series of vulnerabilities affecting Firefox were disclosed, including CVE-2026-74934 to CVE-2026-74990.
Linuxsecurity
2026-08-18
CVE-2026-74969 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74972 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74962 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74934 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74957 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74946 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74971 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74965 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-74953 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE