CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Mozilla security advisory (AV26-840)

unknown
Serial Number: AV26-840 Date: August 21, 2026 As of August 18, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox versions prior to 154 Firefox ESR versions prior to 115.39 versions prior to 140.14 versions prior to 153.1 Thunderbird versions prior to 140.14 versions prior to 153.1 versions prior to 154 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Mozilla Foundation Security Advisories — Mozilla

CSIRTS triage

vendor: Mozillaproduct: FirefoxRemote code executionInformation disclosureOtheraffected: Firefox prior to 154; ESR prior to 115.39; Thunderbird prior to 140.14, 153.1, 154
What
Multiple unspecified vulnerabilities in Mozilla Firefox, Firefox ESR, and Thunderbird.
Who is affected
Users and administrators running Firefox versions below 154, ESR below 115.39, and Thunderbird below 140.14 or 153.1.
Urgency
High; Firefox and Thunderbird are widely deployed and exploits are likely to follow disclosure; immediate patching recommended.
Action
Update Firefox to version 154 or later, Firefox ESR to 115.39 or later, and Thunderbird to 140.14, 153.1, or 154 as appropriate.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Firefox

Get an email when a new Firefox advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-840

More from Canadian Centre for Cyber Security