Mozilla security advisory (AV26-976)
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Firefox
- Reported by
- 1 outlet
As of September 29, 2026, Mozilla is affected by vulnerabilities in the following products:
- Firefox ESR
- Versions prior to 153.4
- Versions prior to 140.17
- Versions prior to 115.42
- Firefox
- Versions prior to 157
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-29 19:17 UTC
Related stories
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- [Control systems] Hitachi security advisory (AV26-975)
Canadian Centre for Cyber Security · 2026-09-29
- TeamViewer security advisory (AV26-977)
Canadian Centre for Cyber Security · 2026-09-29
- Hackers exploit Citrix NetScaler zero-day to deploy web shells
BleepingComputer · 2026-09-29 · exploited