What is CVE-2026-74946?
CVE-2026-74946 is a privilege escalation vulnerability in the Graphics: CanvasWebGL component of Firefox and Thunderbird, caused by incorrect boundary conditions. Users must immediately update to the fixed versions (Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, 140.14, 153.1) to mitigate the risk.
Azərbaycanca: CVE-2026-74946, Firefox ve Thunderbird-də Graphics: CanvasWebGL komponentində sərhəd şərtlərinin yanlış işlənməsi səbəbindən imtiyaz yüksəltməyə (privilege escalation) imkan verən zəiflikdir. Təsirə məruz qalan sistemlərdə istifadəçilər dərhal qeyd olunan düzəldilmiş versiyalara (Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, 140.14, 153.1) yeniləmə etməlidirlər.
FAQ2
Which products are affected by this vulnerability?
This vulnerability affects the Firefox browser and the Thunderbird email client.
How can users protect themselves from this vulnerability?
Users must immediately update to the fixed versions: Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, 140.14, 153.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.