# Mozilla patches dozens of Firefox flaws

Published: 2026-09-30 · Severity: routine
Canonical: https://vorant.io/reports/996c8c8d-1630-5143-8ae5-1aa5b0e6ad87/mozilla-patches-dozens-of-firefox-flaws

> CERT-FR relays Mozilla's September 2026 security bulletins fixing dozens of Firefox and Firefox ESR vulnerabilities including privilege escalation and DoS risks.

CERT-FR has published an advisory relaying four Mozilla security bulletins (MFSA2026-97 through MFSA2026-100) dated 29 September 2026, covering a large batch of vulnerabilities in Firefox and Firefox ESR. Affected versions include Firefox ESR before 115.42, 140.17 and 153.4, and Firefox before version 157. The vulnerabilities collectively allow an attacker to achieve privilege escalation, remote denial of service, security policy bypass, and disclosure of confidential data; some impacts are unspecified by the vendor.

No evidence of in-the-wild exploitation is noted in this advisory. The recommended action is to apply Mozilla's official patches referenced in the linked security bulletins as soon as possible. Given the volume of CVEs (over 80) bundled into a single vendor release cycle, organizations should prioritize deployment of the latest Firefox and Firefox ESR builds across their fleet through standard patch management processes.

This is a routine vendor patch cycle bulletin from a national CERT, not a report of targeted exploitation or a novel attack technique. Defenders should treat this as standard browser patching hygiene, verifying that managed Firefox/Firefox ESR deployments are updated to the fixed versions listed above.

## Mentioned in this report

- Vulnerabilities: CVE-2026-100756, CVE-2026-100757, CVE-2026-100758, CVE-2026-100759, CVE-2026-100760, CVE-2026-100761, CVE-2026-100762, CVE-2026-100763, CVE-2026-100764, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100768, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-92035, CVE-2026-96869

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1240

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/996c8c8d-1630-5143-8ae5-1aa5b0e6ad87/mozilla-patches-dozens-of-firefox-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
