VORANT. Threat Intelligence Research Sign in Create a free account

Mozilla patches dozens of Firefox flaws

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR relays Mozilla's September 2026 security bulletins fixing dozens of Firefox and Firefox ESR vulnerabilities including privilege escalation and DoS risks.

CERT-FR has published an advisory relaying four Mozilla security bulletins (MFSA2026-97 through MFSA2026-100) dated 29 September 2026, covering a large batch of vulnerabilities in Firefox and Firefox ESR. Affected versions include Firefox ESR before 115.42, 140.17 and 153.4, and Firefox before version 157. The vulnerabilities collectively allow an attacker to achieve privilege escalation, remote denial of service, security policy bypass, and disclosure of confidential data; some impacts are unspecified by the vendor.

No evidence of in-the-wild exploitation is noted in this advisory. The recommended action is to apply Mozilla's official patches referenced in the linked security bulletins as soon as possible. Given the volume of CVEs (over 80) bundled into a single vendor release cycle, organizations should prioritize deployment of the latest Firefox and Firefox ESR builds across their fleet through standard patch management processes.

This is a routine vendor patch cycle bulletin from a national CERT, not a report of targeted exploitation or a novel attack technique. Defenders should treat this as standard browser patching hygiene, verifying that managed Firefox/Firefox ESR deployments are updated to the fixed versions listed above.

Mentioned in this report

Vulnerabilities CVE-2026-100756CVE-2026-100757CVE-2026-100758CVE-2026-100759CVE-2026-100760CVE-2026-100761CVE-2026-100762CVE-2026-100763CVE-2026-100764CVE-2026-100765CVE-2026-100766CVE-2026-100767CVE-2026-100768CVE-2026-100769CVE-2026-100770CVE-2026-100771CVE-2026-100772CVE-2026-100773CVE-2026-100774CVE-2026-100775CVE-2026-100776CVE-2026-100777CVE-2026-100778CVE-2026-100779CVE-2026-100780CVE-2026-100781CVE-2026-100782CVE-2026-100783CVE-2026-100784CVE-2026-100785CVE-2026-100786CVE-2026-100787CVE-2026-100788CVE-2026-100789CVE-2026-100790CVE-2026-92035CVE-2026-96869

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1240

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,423 reports from 154 sources, 2,072 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs