Vulnerabilities & Exploits

Debian patches firefox-esr for 36 security flaws

Debian released DSA-6178-1 updating firefox-esr to fix 36 CVEs that permit code execution, sandbox escape, data disclosure, denial of service, and privilege escalation. The advisory applies to the Debian package firefox-esr and Mozilla Firefox ESR; administrators should confirm they are running the updated package. The fixes address CVEs ranging from CVE-2025-59375 through CVE-2026-4721.

1 source · Mar 29

CVEs in this update

36 CVEs

Across F5OS, BIG-IP, Nessus Network Monitor, and related packages.

16 critical · 20 high · 0 medium · 0 low

0 in CISA KEV · 1 with EPSS above 1%

Highest severity: CVE-2026-4689 · 10.0 CRITICAL

Highest EPSS: CVE-2025-59375 · 1.3%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-30

Every edition of this story: Debian patches firefox-esr for 36 security flaws

More from today