What is CVE-2026-74952?
CVE-2026-74952 is a privilege escalation vulnerability found in the Application Update component of Firefox and Thunderbird. This flaw could allow malicious actors to gain higher-level permissions on the system. The issue has been resolved in Firefox 154 and Thunderbird 154, and users are strongly advised to update to these versions immediately.
Azərbaycanca: CVE-2026-74952, Firefox və Thunderbird-in Application Update komponentində aşkar edilmiş imtiyaz yüksəltmə (privilege escalation) zəifliyidir. Bu boşluq vasitəsilə zərərli aktorlar sistemdə daha yüksək icazələr əldə edə bilər. Bu problem Firefox 154 və Thunderbird 154 versiyalarında aradan qaldırılıb, istifadəçilərə dərhal bu versiyalara yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269; shared vendors: Firefox, Thunderbird
FAQ2
Which products are affected by CVE-2026-74952?
This vulnerability affects the Application Update component of Firefox and Thunderbird.
What is the available solution for CVE-2026-74952?
Users are strongly advised to update to Firefox 154 and Thunderbird 154 immediately, as the issue has been resolved in these versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.