Medium severity4.3NVD Advisory· Published Jul 14, 2026· Updated Jul 22, 2026
CVE-2026-15718
CVE-2026-15718
Description
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.
Affected products
10cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*range: <152.0.6
- (no CPE)range: >=152.0,<152.0.6
- Range: >=140.13
- osv-coords7 versionspkg:rpm/almalinux/firefoxpkg:rpm/almalinux/firefox-x11pkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 140.13.0-1.el10_2+ 6 more
- (no CPE)range: < 140.13.0-1.el10_2
- (no CPE)range: < 140.13.0-1.el9_8.alma.1
- (no CPE)range: < 140.13.0-1.el10_2.alma.1
- (no CPE)range: < 140.13.0-160000.1.1
- (no CPE)range: < 152.0.6-1.1
- (no CPE)range: < 140.13.0-1.1
- (no CPE)range: < 140.13.0-1.1
Patches
Vulnerability mechanics
References
4- www.mozilla.org/security/advisories/mfsa2026-67/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
- www.mozilla.org/security/advisories/mfsa2026-70/nvd
- www.mozilla.org/security/advisories/mfsa2026-72/nvd
News mentions
2- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security FlawsThe Hacker News · Jul 15, 2026
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesSecurityWeek · Jul 15, 2026