Mozilla security advisory (AV26-868)
Canada's Cyber Centre reports Mozilla vulnerabilities fixed in Firefox 155 and Firefox ESR 115.40, 140.15, and 153.2.
Canadian Centre for Cyber Security advisory AV26-868, dated September 1, 2026, notes vulnerabilities in Firefox (versions prior to 155) and Firefox ESR (prior to 115.40, 140.15, and 153.2). The bulletin links to Mozilla's security advisories and urges users and administrators to update. No CVE identifiers or exploitation details are provided.
- Firefox ESR branches 115, 140, and 153 plus Firefox 155 receive security fixes
- Advisory AV26-868 provides no CVE IDs or exploitation details
- Users and administrators urged to update browsers promptly
Full article103 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-868
Date: September 1, 2026
As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products:
Firefox ESR
Versions prior to 115.40
Versions prior to 140.15
Versions prior to 153.2
Firefox
Versions prior to 155
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla
Security Vulnerabilities fixed in Firefox ESR 140.15 — Mozilla
Security Vulnerabilities fixed in Firefox ESR 153.2 — Mozilla
Security Vulnerabilities fixed in Firefox 155 — Mozilla
Mozilla Foundation Security Advisories — Mozilla
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-868