What is CVE-2026-74949?
This vulnerability is a privilege escalation flaw caused by a use-after-free condition in the Canvas2D graphics component of Firefox, Firefox ESR, and Thunderbird. Affected systems should be updated to Firefox 154, Thunderbird 154, or their corresponding ESR versions to mitigate the issue.
Azərbaycanca: Bu zəiflik Firefox, Firefox ESR və Thunderbird-in Graphics: Canvas2D komponentində use-after-free səbəbindən imtiyaz artımına yol açır. Təsirə məruz qalan sistemlər üçün Firefox 154, Thunderbird 154 və müvafiq ESR versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which software products are affected by CVE-2026-74949?
This vulnerability affects the Graphics: Canvas2D component of Firefox, Firefox ESR, and Thunderbird.
What versions should be applied to mitigate CVE-2026-74949?
Affected systems should be updated to Firefox 154, Thunderbird 154, or their corresponding ESR versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.