Junglewise Threat Intelligence

CVE-2026-74985: Mozilla Firefox privilege escalation in Enterprise Policies

CVE-2026-74985 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox, Thunderbird, and their ESR variants contain a privilege escalation vulnerability in the Enterprise Policies component that could allow an attacker to escalate their access level on an affected system. An exploit of this vulnerability could enable unauthorized access to sensitive data, system compromise, or lateral movement within a corporate network.

Technical details

CVE-2026-74985 is a privilege escalation vulnerability in the Enterprise Policies component affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The vulnerability allows an attacker to escalate privileges through improper handling of policy enforcement mechanisms. The exact attack vector and preconditions are not publicly detailed, though the high CVSS score (9.8) indicates network accessibility without authentication or user interaction required. The vulnerability has been patched in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 153.1

Timeline

  • 2026-08-18: disclosed: Vulnerability disclosed by Mozilla
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats