Mozilla released security advisories addressing vulnerabilities in Firefox and Firefox ESR, prompting the Canadian Centre for Cyber Security to urge organizations and users to apply updates. The affected versions included Firefox releases prior to 149, Firefox ESR releases prior to 115.34, and Firefox ESR releases prior to 140.9, according to the earlier advisory.
A subsequent Mozilla advisory issued additional fixes for the same product lines, affecting Firefox versions prior to 149.0.2, Firefox ESR versions prior to 115.34.1, and Firefox ESR versions prior to 140.9.1. The Canadian Centre for Cyber Security described the notices as vendor patch and mitigation guidance and advised administrators to review Mozilla’s bulletins and deploy the necessary updates across exposed systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Mozilla published additional security advisories on April 7, 2026 for vulnerabilities affecting Firefox versions prior to 149.0.2, Firefox ESR versions prior to 115.34.1, and Firefox ESR versions prior to 140.9.1. The notice described this as a vendor patch and mitigation update rather than active exploitation.
Mozilla published security advisories on March 24, 2026 addressing vulnerabilities affecting Firefox versions prior to 149, Firefox ESR versions prior to 115.34, and Firefox ESR versions prior to 140.9. The Canadian Centre for Cyber Security advised users and administrators to review the advisories and apply the updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.