
Mozilla Releases Firefox Updates to Patch Two Critical Vulnerabilities with Public Exploit Code
cybersecurityvulnerabilitiesfirefoxmozillaCVEpatchexploitwebassemblyDOMsite_isolation
Mozilla released updates to address two critical vulnerabilities in Firefox, identified as CVE-2026-15718 and CVE-2026-15719, with exploit code publicly available. CVE-2026-15718 involves an invalid pointer in the JavaScript: WebAssembly component, while CVE-2026-15719 affects site isolation in the DOM: Navigation component. The company confirmed awareness of the public exploit code but did not disclose active exploitation in the wild. No specific patch release date was provided, though the updates were announced in July 2026. The flaws were detailed in a security notice alongside updates for Chrome, Adobe, and VMware products.