Firefox 154 patches a CVSS 10.0 sandbox escape that needs no user interaction
On August 18, 2026, Mozilla fixed CVE-2026-75874, a sandbox escape in Firefox’s Remote Settings component rated CVSS 10.0 and exploitable with no interaction at all. Update Firefox and Thunderbird 154 across the fleet without waiting.