Firefox RCE patched in version 152.0.4
Mozilla patched CVE-2026-14241, an arbitrary code execution vulnerability affecting Firefox versions prior to 152.0.4.
The French national cybersecurity agency CERT-FR has published an advisory regarding a vulnerability in Mozilla Firefox that enables arbitrary code execution. The flaw, tracked as CVE-2026-14241, affects all Firefox versions prior to 152.0.4.
Mozilla has released Firefox 152.0.4 to address this vulnerability. Organizations and users running affected versions should apply the update promptly to mitigate the risk of exploitation. The advisory references Mozilla's security bulletin mfsa2026-62, published on June 30, 2026, which contains detailed patch information.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0820
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free