What is CVE-2026-74948?
CVE-2026-74948 is an information disclosure vulnerability in the Graphics component affecting Firefox and Thunderbird. It was resolved in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. Users should immediately update to the fixed versions.
Azərbaycanca: CVE-2026-74948 Firefox və Thunderbird-in Graphics komponentində məlumat sızmasına (information disclosure) səbəb olan boşluqdur. Təsirə məruz qalan versiyalar Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, və Thunderbird 153.1 yeniləmələri ilə aradan qaldırılıb. İstifadəçilər göstərilən versiyalara təcili yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which products are affected by CVE-2026-74948?
This vulnerability affects the Graphics component of Firefox and Thunderbird.
To which versions should I update to be protected from CVE-2026-74948?
You must immediately update to Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.