Medium severity5.4NVD Advisory· Published Jul 14, 2026· Updated Jul 22, 2026
CVE-2026-15719
CVE-2026-15719
Description
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Affected products
10cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*range: <152.0.6
- (no CPE)range: before 152.0.6
- Range: before 140.13
- osv-coords7 versionspkg:rpm/almalinux/firefoxpkg:rpm/almalinux/firefox-x11pkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 140.13.0-1.el10_2+ 6 more
- (no CPE)range: < 140.13.0-1.el10_2
- (no CPE)range: < 140.13.0-1.el9_8.alma.1
- (no CPE)range: < 140.13.0-1.el10_2.alma.1
- (no CPE)range: < 140.13.0-160000.1.1
- (no CPE)range: < 152.0.6-1.1
- (no CPE)range: < 140.13.0-1.1
- (no CPE)range: < 140.13.0-1.1
Patches
Vulnerability mechanics
References
5News mentions
2- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security FlawsThe Hacker News · Jul 15, 2026
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesSecurityWeek · Jul 15, 2026