Mozilla Foundation Security Advisory 2026-91
Security Vulnerabilities fixed in Firefox ESR 115.41
- Announced
- September 15, 2026
- Impact
- high
- Products
- Firefox ESR
- Fixed in
-
- Firefox ESR 115.41
Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component
- Reporter
- Jacolon Walker
- Impact
- high
References
#CVE-2026-92015: Privilege escalation in the WebExtensions component
- Reporter
- Quy Pham
- Impact
- high
References
#CVE-2026-92017: Privilege escalation in the DOM: Service Workers component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component
- Reporter
- Quy Pham
- Impact
- high
References
#CVE-2026-92019: Mitigation bypass in the Remote Settings Client component
- Reporter
- Shu Takahashi
- Impact
- high
References
#CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component
- Reporter
- Rintaro Kawasugi
- Impact
- high
References
#CVE-2026-92022: Use-after-free in the DOM: HTML Parser component
- Reporter
- Seohyeon Maeng
- Impact
- high
References
#CVE-2026-92023: Use-after-free in the XML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92024: Use-after-free in the SVG component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92025: Use-after-free in the DOM: Navigation component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92027: Use-after-free in the DOM: Streams component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92028: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-92029: Use-after-free in the SVG component
- Reporter
- Mozilla
- Impact
- high