CVE-2026-74935
Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14,
CVSS
8.8
Alto
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 18 ago 2026 · Última mod.: 21 ago 2026 · CWE-269
0.3%EPSS · 30 días0.3%
2026-08-192026-09-10
Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2051013
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-74/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-75/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-76/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-77/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-78/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-79/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-80/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-85979——
———Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system.5hCVE-2026-749257.2 ALT—
——0The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.4hCVE-2026-879588.1 ALT—
——0IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.6hCVE-2026-757778.8 ALT—
——0IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.6hCVE-2026-93276.3 MED—
——0IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.3hCVE-2026-888918.3 ALT—
——0OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.1d