Linuxsecurity Oracle Linux 10 Firefox Security Advisories Released on July 20, 2026
Article Content
- •Oracle released critical security advisories for Firefox on July 20, 2026.
- •Multiple CVEs, including CVE-2026-7320 and CVE-2026-8092, are associated with the vulnerabilities.
- •Users of Oracle Linux 10 are urged to update Firefox to prevent potential remote code execution.
On July 20, 2026, Oracle released two security advisories for Firefox in Oracle Linux 10, addressing critical vulnerabilities. The advisories include ELSA-2026-19157 and ELSA-2026-19160, with related CVEs including CVE-2026-7320, CVE-2026-7321, CVE-2026-7322, CVE-2026-7323, CVE-2026-8090, and CVE-2026-8092. The vulnerabilities could potentially allow for remote code execution and other exploits if left unpatched. Affected systems include Oracle Linux 10 with Firefox versions 140.10.x and 140.12.x. Users are urged to update their systems immediately to mitigate risks. The advisories detail fixes for default preferences and updates to the Extended Support Release (ESR) versions of Firefox. The advisories emphasize the importance of applying the patches to protect against potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-12289 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…