PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74985 Mozilla CVE debrief

CVE-2026-74985 is a critical vulnerability in the Enterprise Policies component of Mozilla products, including Firefox, Firefox ESR, and Thunderbird. The vulnerability has a CVSS score of 9.8 and allows for privilege escalation. It was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Limited evidence suggests that this is a privilege escalation issue; further analysis is required to fully understand the vulnerability. Organizations and individuals using these products should verify their inventory and apply updates to mitigate the vulnerability.

Vendor
Mozilla
Product
Firefox
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-25
Advisory published
2026-08-18
Advisory updated
2026-08-25

Who should care

Organizations and individuals using Mozilla products, specifically Firefox, Firefox ESR, and Thunderbird, should verify their inventory and apply updates to mitigate the vulnerability. This includes IT administrators, security teams, and individuals responsible for maintaining and securing these products. Additionally, developers and users of these products should be aware of the vulnerability and take necessary precautions to prevent exploitation.

Technical summary

CVE-2026-74985 is a critical vulnerability in the Enterprise Policies component of Mozilla products, including Firefox, Firefox ESR, and Thunderbird. The vulnerability has a CVSS score of 9.8 and allows for privilege escalation. It was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Limited evidence suggests that this is a privilege escalation issue; further analysis is required to fully understand the vulnerability. The vulnerability affects the Enterprise Policies component, which could allow an attacker to gain elevated privileges.

Defensive priority

Mozilla products are widely used; verify your inventory for Firefox, Firefox ESR, and Thunderbird versions prior to 154, 153.1, and 154, 153.1 respectively; apply updates immediately if vulnerable.

Recommended defensive actions

  • Verify your inventory for Firefox, Firefox ESR, and Thunderbird versions prior to 154, 153.1, and 154, 153.1 respectively.
  • Apply updates immediately if vulnerable.
  • Monitor for potential exploitation attempts.
  • Review and update incident response plans.
  • Perform a thorough review of system configurations and user privileges.
  • Implement additional monitoring and logging to detect potential exploitation attempts.
  • Conduct regular security audits to ensure compliance with organizational security policies.

Evidence notes

The CVE-2026-74985 record indicates a critical vulnerability in the Enterprise Policies component of Mozilla products, with a CVSS score of 9.8. It was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Limited evidence suggests that this is a privilege escalation issue; further analysis is required to fully understand the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74985 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74985

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74985 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74985

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.