Mozilla has fixed two critical vulnerabilities in Firefox and openly states that exploit code for both is already public. On the same day, Google fixed 15 issues in Chrome, two of which were critical. For a small company, it’s a two-minute check on each computer.
These are CVE-2026-15718 and CVE-2026-15719, both classified as “critical” and patched in Firefox 152.0.6. Mozilla notes that it has not yet seen any actual attacks, but that is no reason to delay: once exploitation instructions are publicly available, it is only a matter of days—not months—before the first campaigns emerge.
The Chrome update was announced on the same day: 15 issues fixed—two of them critical—in version 150.0.7871.124. Checking each computer in the company:
- Firefox: Menu, then Help, then About Firefox. It should say 152.0.6.
- Chrome: Menu, then Help, then About Google Chrome. It should say 150.0.7871.124 or newer.
- Restart your browser after the update.
The last step is the one that trips up most companies: the update downloads in the background but isn’t applied until after a restart, and tabs remain open for weeks on office computers. Basically, a company can be “up to date” on paper but not actually up to date in reality. It’s not an “stop everything” emergency—it’s the kind of thing that takes two minutes to fix today. If you want browser and system updates to be tracked centrally, without relying on each colleague’s memory, you can email us at [email protected] or call us at +40 712 605 222.
Source: Mozilla | https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/
This article was generated with AI assistance.