Mozilla released Firefox 155 and maintenance updates for Firefox ESR 153.2.0, 140.15.0, and 115.40.0. The release remediates 109 security vulnerabilities, including memory-safety issues that malicious websites could potentially exploit for arbitrary code execution or other browser compromise; organizations should prioritize deployment across managed Firefox installations.
Firefox 155 also introduces an experimental AI-assisted “Smart Window” feature for a limited user set, alongside web-platform, developer-tool, PDF viewer, Android, HTTP/3, WebAssembly, CSS, JSON, WebTransport, and Windows controller updates. Several experimental platform capabilities remain disabled by default and can be enabled through about:config; the release also changes captive-portal detection from detectportal.firefox.com to firefox-portal-detection.com.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Slackware published security advisory SSA_2026-247-02 to patch Mozilla Firefox packages on Slackware 15.0 and -current for eleven CVEs, including critical CVE-2026-84143 (CVSS 9.8). The advisory indicated that no known exploits were available.
Debian published DSA-6481 to patch a vulnerability affecting Firefox ESR localization packages on Debian Linux 13.0, including firefox-esr-l10n-all and numerous language-specific packages. The advisory stated that no known exploits were available.
CVE-2026-84122 was published and identified as unpatched for potentially affected Ubuntu LTS and Debian releases, including Mozilla JavaScript, Firefox ESR, and Thunderbird-related packages. The vulnerability is network-accessible, requires user interaction, and had no known exploits available.
Fedora advisory FEDORA-2026-208add2041 patched Firefox and NSS packages in Fedora 43 for 26 CVEs, including the critical CVE-2026-84143 (CVSS 9.8). The advisory reported no known public exploits.
Fedora published advisory FEDORA-2026-42a3a95e62 for Firefox and NSS packages in Fedora 44, addressing 26 CVEs including CVE-2026-84143, a critical network-reachable flaw. The advisory reported no known exploits for the addressed vulnerabilities.
Vulnerability information was published for six flaws affecting Mozilla Firefox ESR 115.40: CVE-2026-75874, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84131, and CVE-2026-84145. CVE-2026-75874 was rated critical with a network-exploitable CVSS v3 vector requiring no privileges or user interaction.
Mozilla security updates remediated 11 vulnerabilities across Firefox, Firefox ESR, and Thunderbird, including three rated critical and eight rated high. Thunderbird versions earlier than 155, 153.2, and 140.15 were affected; the issues could enable arbitrary code execution, privilege escalation, or security-restriction bypass.
Mozilla released Firefox 155 alongside Firefox ESR 153.2.0, 140.15.0, and 115.40.0. The release introduced the limited experimental Smart Window AI feature and addressed 109 vulnerabilities, including flaws that could permit code execution or otherwise compromise browser security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcegmcsirt.gm
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcedeveloper.mozilla.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.