Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
## This update for MozillaFirefox fixes the following issue: * Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649): * CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component. * CVE-2026-15719: Site isolation issue in the DOM: Navigation component. * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component.
* bsc#1271649
Cross-
* CVE-2026-15718
* CVE-2026-15719
* CVE-2026-16349
* CVE-2026-16350
* CVE-2026-16351
* CVE-2026-16352
* CVE-2026-16353
* CVE-2026-16354
* CVE-2026-16355
* CVE-2026-16356
* CVE-2026-16357
* CVE-2026-16358
* CVE-2026-16359
* CVE-2026-16360
* CVE-2026-16361
* CVE-2026-16362
* CVE-2026-16363
* CVE-2026-16368
* CVE-2026-16369
* CVE-2026-16371
* CVE-2026-16374
* CVE-2026-16375
* CVE-2026-16377
* CVE-2026-16379
* CVE-2026-16381
* CVE-2026-16383
* CVE-2026-16387
* CVE-2026-16390
* CVE-2026-16391
* CVE-2026-16396
* CVE-2026-16405
* CVE-2026-16412
CVSS scores:
* CVE-2026-15718 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2026-15719 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Get the latest Linux and open source security news straight to your inbox.