Debian Firefox-ESR Vulnerabilities Prompt Urgent Patching

Debian Firefox-ESR Vulnerabilities Prompt Urgent Patching

First seen 4 Sep 2026, 10:30 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Debian has released critical security updates for Firefox-ESR due to vulnerabilities including CVE-2026-16365, which was published on July 21, 2026. The vulnerabilities affect Debian 12 (bookworm) and Debian 13 (trixie) users, with patches available in versions 140.15.0esr-1~deb12u1 and 140.15.0esr-1~deb13u1, respectively. The vulnerabilities could allow for code execution, posing a significant risk to users who do not apply the updates. Administrators are advised to upgrade their firefox-esr packages immediately to mitigate potential exploitation. The urgency is underscored by the critical nature of the vulnerabilities and the potential for active exploitation. Users should refer to the security tracker pages for detailed status and guidance on applying updates.

Key Points: • Critical vulnerabilities in Firefox-ESR require immediate patching. • CVE-2026-16365 was published on July 21, 2026, affecting Debian systems. • Patches are available for both Debian 12 (bookworm) and Debian 13 (trixie).

Ask AI about this cluster

Timeline

2026-07-21
CVE-2026-16365 published
CVE-2026-16365 disclosed, highlighting critical vulnerabilities in Firefox-ESR.
Linuxsecurity
2026-09-02
Debian releases patch for trixie
Debian released version 140.15.0esr-1~deb13u1 to fix critical issues in Firefox-ESR for Debian 13.
Linuxsecurity
2026-09-04
Debian releases patch for bookworm
Debian released version 140.15.0esr-1~deb12u1 to address vulnerabilities in Firefox-ESR for Debian 12.
Linuxsecurity