What is CVE-2026-74954?
This vulnerability allows information disclosure through a side-channel attack in the 'Storage: Cache API' component of Firefox, Firefox ESR, and Thunderbird. Users are advised to update immediately to Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1 to mitigate the risk.
Azərbaycanca: Bu kritik zəiflik Firefox, Firefox ESR və Thunderbird brauzerlərinin 'Storage: Cache API' komponentində yan kanal (side-channel) vasitəsilə məxfi məlumatların sızmasına imkan verir. İstifadəçilərə dərhal Firefox 154, Firefox ESR 153.1, Thunderbird 154 və Thunderbird 153.1 versiyalarına yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which component of which software is affected by CVE-2026-74954?
This vulnerability affects the 'Storage: Cache API' component of Firefox, Firefox ESR, and Thunderbird.
Which versions should users update to in order to mitigate the risk associated with CVE-2026-74954?
Users are advised to immediately update to Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.