Linuxsecurity Oracle Linux 7 Firefox Security Updates Address Multiple CVEs
Article Content
- •Oracle released critical security updates for Firefox on Oracle Linux 7.
- •The updates address 39 CVEs, including several high-severity vulnerabilities.
- •Immediate action is recommended for users to apply the patches to prevent exploitation.
On June 12, 2026, Oracle released important security updates for Firefox on Oracle Linux 7, addressing multiple vulnerabilities. The updates include versions 140.8.0 ESR and 140.9.0 ESR, which fix a total of 39 CVEs, including CVE-2026-2447, CVE-2026-4684, and CVE-2026-4685. The vulnerabilities range from critical to high severity, affecting various components of the Firefox browser. Users are urged to update their systems to mitigate potential exploitation. The updates are particularly relevant for organizations relying on Oracle Linux 7 for their operations. The patches are available for immediate deployment, and administrators are advised to prioritize these updates to ensure security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track CVE-2025-14321 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…