Debian released DSA-6178-1 updating firefox-esr to fix 36 CVEs that permit code execution, sandbox escape, data disclosure, denial of service, and privilege escalation. The advisory applies to the Debian package firefox-esr and Mozilla Firefox ESR; administrators should confirm they are running the updated package. The fixes address CVEs ranging from CVE-2025-59375 through CVE-2026-4721.
Part of the PlainSec briefing for 2026-03-30