Complete feed
Security advisories & CVEs
7850 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-74961] Side-channel in the Web Audio component
Side-channel in the Web Audio component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-208.
Medium [CVE-2026-74955] Privilege escalation in the Request Handling component
Privilege escalation in the Request Handling component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-551.
Medium [CVE-2026-74956] Same-origin policy bypass in the DOM: Service Workers component
Same-origin policy bypass in the DOM: Service Workers component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346.
Medium [CVE-2026-74954] Information disclosure due to side-channel in the Storage: Cache API component
Information disclosure due to side-channel in the Storage: Cache API component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-524.
Medium [CVE-2026-74958] Information disclosure in the WebRTC component
Information disclosure in the WebRTC component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-201.
Medium [CVE-2026-74950] Privilege escalation in the Downloads API component
Privilege escalation in the Downloads API component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-648.
Medium [CVE-2026-74952] Privilege escalation in the Application Update component
Privilege escalation in the Application Update component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-250.
Medium [CVE-2026-74951] Clickjacking issue in Firefox for Android
Clickjacking issue in Firefox for Android. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1021.
Medium [CVE-2026-74974] Same-origin policy bypass in the Graphics: ImageLib component
Same-origin policy bypass in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74973] Race condition, use-after-free in the Graphics component
Race condition, use-after-free in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74969] Use-after-free in the Layout: Text and Fonts component
Use-after-free in the Layout: Text and Fonts component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74971] Information disclosure in the DOM: UI Events & Focus Handling component
Information disclosure in the DOM: UI Events & Focus Handling component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-360. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74972] Information disclosure in the DOM: Push Subscriptions component
Information disclosure in the DOM: Push Subscriptions component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74965] Privilege escalation in the Shell Integration component
Privilege escalation in the Shell Integration component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74967] Same-origin policy bypass in the Audio/Video: Playback component
Same-origin policy bypass in the Audio/Video: Playback component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74963] Same-origin policy bypass in the Networking: Cookies component
Same-origin policy bypass in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74964] Integer overflow in the Graphics component
Integer overflow in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74960] Site isolation issue in the WebExtensions component
Site isolation issue in the WebExtensions component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74959] Mitigation bypass in the Storage: Cache API component
Mitigation bypass in the Storage: Cache API component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-74962] Site isolation issue in the Networking: Cookies component
Site isolation issue in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1100. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.