CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0242 [1.00] [M/H] Vulnerabilities fixed in Mozilla Firefox

unknownCVE-2026-15719CVE-2026-15718
Mozilla has fixed vulnerabilities in Firefox, specifically in version 152.0.6. Due to a combination of two vulnerabilities, it is possible for malicious actors to execute harmful code on victims' systems remotely. For successful exploitation, users must visit a malicious website or a legitimate website with malicious ads. Mozilla indicates that exploit code for the vulnerabilities is publicly available. This increases the likelihood of exploitation. To date, no attacks have been observed that exploit these vulnerabilities in the wild. The technical details of the vulnerabilities have not been disclosed, but the presence of exploit code indicates a potential risk if the update is not applied.

CSIRTS triage

What
Exploitation of vulnerabilities could allow remote code execution via malicious websites.
Who is affected
Users of Firefox version 152.0.6 who visit malicious websites.
Urgency
Remediation is urgent as exploit code is publicly available, increasing the risk of exploitation.
Action
Users should update to the latest version of Firefox.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Firefox

Get an email when a new Firefox advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-16
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0242

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-15719coverage & exploitation statusNVD · CVE.org
CVE-2026-15718coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories