Red Hat Firefox 140.15 Updates Extended RHEL Branches
Quick Answer
Red Hat published RHSA-2026:76746 and RHSA-2026:76741 and RHSA-2026:76740 and RHSA-2026:76742 for Firefox ESR packages for RHEL 7 ELS, RHEL 8.8 E4S/TUS, and RHEL 9.2/9.4 E4S. Match entitled deployments to the exact advisory relationships, apply firefox 140.15.0-1 on the advisory-listed RHEL branches, validate dependent operations, and preserve evidence.
Validate Firefox Scope And Apply The Red Hat Fix
What to do now: Inventory Firefox ESR packages for RHEL 7 ELS, RHEL 8.8 E4S/TUS, and RHEL 9.2/9.4 E4S, confirm the exact entitled branch and installed build or digest, apply the advisory-listed content, validate representative services, and document exceptions.
Last verified: 2026-10-06 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Firefox ESR packages for RHEL 7 ELS, RHEL 8.8 E4S/TUS, and RHEL 9.2/9.4 E4S |
|---|---|
| Advisory | RHSA-2026:76746 / RHSA-2026:76741 / RHSA-2026:76740 / RHSA-2026:76742 |
| CVEs | CVE-2026-16365, CVE-2026-75874, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84124, CVE-2026-84131, CVE-2026-84143, CVE-2026-84145 |
| Authoritative release date | 2026-10-06 14:06:02 UTC |
| Authority revision date | 2026-10-06 14:09:50 UTC |
| Affected versions | The supported Firefox ESR packages for RHEL 7 ELS, RHEL 8.8 E4S/TUS, and RHEL 9.2/9.4 E4S builds identified as affected by the advisory product-status relationships. |
| Fixed version | firefox 140.15.0-1 on the advisory-listed RHEL branches |
| CVSS base score | 6.1 / 7.5 (CVSS v3.1) |
| CVSS severity | Medium to High |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Red Hat released Firefox 140.15.0 packages for ten browser vulnerabilities on multiple extended-support RHEL 7, 8, and 9 branches.
What To Validate Now
- Inventory. Locate Firefox ESR packages for RHEL 7 ELS, RHEL 8.8 E4S/TUS, and RHEL 9.2/9.4 E4S; record the installed build or digest, repository and entitlement, owner, exposure, dependencies, and maintenance group.
- Establish applicability. Compare each deployment with the product and fixed-status relationships in RHSA-2026:76746 and RHSA-2026:76741 and RHSA-2026:76740 and RHSA-2026:76742. Do not infer applicability from a component name or CVSS rating alone.
- Remediate. Apply firefox 140.15.0-1 on the advisory-listed RHEL branches from the supported Red Hat channel for the exact product branch or architecture.
- Validate. Confirm the resulting package version or immutable digest, exercise representative Firefox services and recovery paths, monitor for regressions, and record the result.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Confirm ELS, E4S, or TUS entitlement; test browser policies, extensions, certificates, proxy behavior, enterprise authentication, and application compatibility. Preserve pre-change versions or digests, logs, installation output, validation evidence, and rollback decisions.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

