Mozilla patched two critical Firefox vulnerabilities last week, but proof-of-concept exploit code for both has now been published online, increasing the risk that attackers will start using them.
- What it is: CVE-2026-15718 (a WebAssembly memory bug) and CVE-2026-15719 (a site isolation flaw) were fixed in Firefox 152.0.6 on 15 July 2026.
- Who is affected: Any business running Firefox on Windows, Mac, or Linux desktops that has not restarted the browser since the update was released.
- What is the risk: With exploit code now public, these flaws are far more likely to be used in real attacks, even though Mozilla has not yet confirmed exploitation in the wild.
- What to do: Firefox updates automatically in the background, but the fix only takes effect after a restart. Staff should be prompted to close and reopen Firefox, or IT should confirm managed devices are running version 152.0.6 or later.
We recommend checking Firefox versions across your business today rather than waiting for the next scheduled restart.
Source: TechTimes, Qualys ThreatPROTECT