Debian issued DSA-6148-1 to ship a firefox-esr security update after Mozilla disclosed numerous vulnerabilities that could enable arbitrary code execution, sandbox escape, same-origin policy bypass, information disclosure, and privilege escalation. The advisory lists a large set of CVEs (including CVE-2026-2757 through CVE-2026-2793, with gaps) and states fixes are available for Debian oldstable (bookworm) in firefox-esr 140.8.0esr-1~deb12u1 (with the notice indicating corresponding updates for stable as well).
The Canadian Centre for Cyber Security published AV26-160, relaying Mozilla’s February 24, 2026 advisories and urging organizations to apply updates for affected Mozilla products, including Firefox ESR prior to 140.8, Firefox ESR prior to 115.33, and Firefox prior to 148. The alert points administrators to Mozilla Foundation Security Advisories 2026-13, 2026-14, and 2026-15 as upstream references for the addressed vulnerabilities and remediation guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-25, dCERT issued advisory 2026-0487 covering multiple vulnerabilities affecting Mozilla Firefox, Firefox ESR, and Thunderbird. The advisory represents additional national CERT notification of the same vulnerability set.
On 2026-02-25, Debian published security advisory DSA-6148-1 for firefox-esr, indicating distribution of a security update in response to the Mozilla vulnerabilities. This reflects downstream remediation for affected Debian users.
On 2026-02-24, the Canadian Centre for Cyber Security issued alert AV26-160 referencing Mozilla's advisories and urged users and administrators to review the guidance and install the necessary updates to remediate the issues.
On 2026-02-24, Mozilla published security advisories 2026-13, 2026-14, and 2026-15 addressing multiple vulnerabilities in Firefox and Firefox ESR. The advisories applied to Firefox versions prior to 148 and Firefox ESR versions prior to 140.8 and 115.33.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
lists.debian.org
Open sourcedcert.de
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.