CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Mozilla security advisory (AV26-726)

critical
Serial number: AV26-726 Date: July 21, 2026 On July 21, 2026, Mozilla published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Firefox ESR – versions prior to 140.13 Firefox ESR – versions prior to 115.38 Firefox – versions prior to 153 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Mozilla Foundation Security Advisory 2026-70 Mozilla Foundation Security Advisory 2026-69 Mozilla Foundation Security Advisory 2026-68 Mozilla Security Advisories

CSIRTS triage

vendor: Mozillaproduct: FirefoxOtheraffected: prior to 153
What
Vulnerabilities have been fixed in Firefox and Firefox ESR products.
Who is affected
Users and administrators of Firefox ESR versions prior to 140.13 and 115.38, and Firefox versions prior to 153.
Urgency
Remediation is critical due to the severity of the vulnerabilities.
Action
Apply the necessary updates to the affected Firefox products.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Firefox

Get an email when a new Firefox advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-726

More from Canadian Centre for Cyber Security