DIRAS TAKE
Treat this as urgent: the issue is rated critical (CVSS 9.8) and no patch is recorded in the supplied facts, so immediately reduce exposure and follow vendor guidance when published.
What is CVE-2026-74985?
An attacker can elevate privileges in Firefox via a flaw in the Enterprise Policies component (CVE-2026-74985). The available facts identify the vulnerability in Firefox's policies functionality but do not list specific affected product versions or describe the required attacker conditions. No vendor patch is recorded in the provided data, and the issue is tracked as a high-severity privilege escalation (CWE-269) that could allow unauthorized privilege gains if exploited. The weakness is classified as CWE-269 (Improper Privilege Management).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74985 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-74985
- Restrict access to systems that manage or apply Enterprise Policies and limit administrative privileges.
- Monitor endpoint and application logs for unexpected privilege changes related to Firefox policy processing.
- Follow Mozilla security advisories and apply official updates as soon as the vendor publishes a patch.
- Isolate high-risk hosts from untrusted networks until a vendor fix is applied.
Frequently asked questions
Is CVE-2026-74985 being actively exploited?
No public reports show active exploitation as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74985?
The provided facts identify the Enterprise Policies component in Firefox but do not list specific affected versions.
Is there a patch for CVE-2026-74985?
According to the supplied data, no patch is recorded as available.
Does CVE-2026-74985 require authentication?
The facts do not specify whether authentication or prior access is required for exploitation.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74985
- cve.org/CVERecord?id=CVE-2026-74985
- bugzilla.mozilla.org/show_bug.cgi?id=2059825
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026