## This update for MozillaFirefox fixes the following issue Update to Firefox Extended Support Release 140.11.0 ESR MFSA 2026-48 (bsc#1265212) * CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component. * CVE-2026-8391: Other issue in the JavaScript Engine component. * CVE-2026-8401: Sandbox escape in the Profile Backup component. * CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component. * CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component. * CVE-2026-8949: Integer overflow in the Widget: Win32 component. * CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component. * CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component.
* bsc#1265212
Cross-
* CVE-2026-8388
* CVE-2026-8391
* CVE-2026-8401
* CVE-2026-8946
* CVE-2026-8947
* CVE-2026-8949
* CVE-2026-8950
* CVE-2026-8953
* CVE-2026-8954
* CVE-2026-8955
* CVE-2026-8956
* CVE-2026-8957
* CVE-2026-8958
* CVE-2026-8959
* CVE-2026-8961
* CVE-2026-8962
* CVE-2026-8968
* CVE-2026-8970
* CVE-2026-8974
* CVE-2026-8975
CVSS scores:
* CVE-2026-8388 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-8391 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8401 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-8401 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-8946 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Get the latest Linux and open source security news straight to your inbox.