Mozilla published security advisories for Firefox 149 and Firefox 149.0.2, disclosing that both releases contain fixes for security vulnerabilities in the browser. The advisories, tracked as MFSA-2026-20 and MFSA-2026-25, indicate that Mozilla issued follow-up updates to address flaws affecting Firefox users.
While the advisories provided here do not include vulnerability synopses, the paired releases show Mozilla delivering both a major browser update and a subsequent point release with additional security fixes. Organizations using Firefox should review the affected versions and prioritize upgrading to the latest available release to reduce exposure to browser-based attacks.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Mozilla published advisory MFSA 2026-20 covering security vulnerabilities fixed in Firefox 149. The advisory was released on 2026-03-24.
Mozilla published advisory MFSA 2026-25 for security vulnerabilities fixed in Firefox 149.0.2. The reference does not provide a reliable publication date, so the event date is left uncertain.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.