On 15 July 2026, Mozilla released an emergency security update for Firefox addressing two critical vulnerabilities—
CVE-2026-15718 and CVE-2026-15719, with Mozilla confirming that exploit code for both flaws is publicly available
. For UK SMEs running Firefox across employee workstations, this represents an immediate security exposure requiring same-day patching.
With around 150 million people worldwide using Firefox
, the attack surface is substantial, and the availability of working exploit code means the risk moves from theoretical to practical within hours.
This article explains what these vulnerabilities mean for UK businesses, how to verify your Firefox installation is protected, and what patch management steps you should implement today.
What Happened on 15 July 2026: Two Critical Firefox Zero-Day Flaws
Mozilla confirmed that working exploit code for both of Firefox’s critical new vulnerabilities is already publicly available, even though no attacks using that code had been observed in the wild at the time of disclosure
. This is significant because once exploit code becomes public, the window between disclosure and active exploitation typically shrinks from weeks to days—or hours.
The emergency update, Firefox 152.0.6, was released on 15 July 2026 as part of a coordinated security response that also saw Google, Adobe, and VMware issue critical patches on the same day.
Chrome, Adobe ColdFusion, and VMware Avi all delivered urgent patches across browser, application server, and network infrastructure categories, with Mozilla’s Firefox update prioritised first given the confirmed public availability of exploit code
.
Why Public Exploit Code Changes the Risk Profile
The difference between a disclosed vulnerability and a disclosed vulnerability with public exploit code is the difference between a locked door with a publicly known weak lock and a locked door with step-by-step instructions for picking it sitting on the doorstep.
When exploit code becomes public:
- Lower-skilled attackers can deploy sophisticated attacks without needing to reverse-engineer the flaw themselves
- Automated exploit frameworks incorporate the code within hours, enabling large-scale scanning for vulnerable systems
- The time between patch availability and active exploitation in the wild typically collapses to 24–72 hours
- Organisations without robust patch management become the easiest targets
Mozilla’s advisory confirms both CVEs have public exploit code, meaning every unpatched Firefox installation is now a known exposure rather than a potential one.
Which Firefox Versions Are Affected?
The vulnerabilities affect all versions of Firefox prior to 152.0.6. This includes:
- Firefox standard release (consumer and business deployments)
- Firefox ESR (Extended Support Release) versions prior to 140.12
- Thunderbird (Mozilla’s email client, which shares the same underlying engine)
If your business uses Firefox as a primary or secondary browser, or if staff use Thunderbird for email, both applications require immediate updates.
The vulnerabilities include information disclosure and sandbox escape in Firefox’s Security: Process Sandboxing component, fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12
.
How UK SMEs Should Respond Today
Step 1: Verify Your Firefox Installation Immediately
Open Firefox, click the menu button (three horizontal lines in the top-right corner), select Help, then About Firefox. The version number will display and Firefox will automatically check for updates. If you’re running any version below 152.0.6, install the update immediately and restart the browser.
Do not wait for automatic updates to roll out across your organisation.
A Chrome browser left open continuously may not receive the security fix for days, even after the update has been released
—the same applies to Firefox if users never close and reopen the browser.
Step 2: Check Thunderbird If You Use It for Email
Thunderbird shares Firefox’s rendering engine and is affected by the same vulnerabilities. Open Thunderbird, go to Help > About Thunderbird, and ensure you’re running version 152 or later (or ESR 140.12 or later if you’re on the Extended Support Release channel).
Step 3: Audit Who Uses Firefox Across Your Business
Many UK SMEs run a mixed browser environment—some staff on Chrome, some on Edge, some on Firefox. If your business doesn’t enforce a single browser through Group Policy or mobile device management, you may not know which machines are running Firefox until you check.
This is a good moment to document which browsers are in use across your organisation and whether you have a process for tracking security updates for each one.
Step 4: Implement a Browser Patch Management Process
This is the third major browser vulnerability cycle in July 2026 alone. We recently covered Google Chrome’s 382-vulnerability update and Microsoft’s record-breaking Patch Tuesday with 569 CVEs. The pattern is clear: vulnerability volumes are rising, patch cycles are accelerating, and businesses without structured patch management are falling further behind.
A basic browser patch management process for UK SMEs should include:
- A documented list of which browsers are in use across the business
- Automatic updates enabled wherever possible (Firefox supports automatic background updates)
- A weekly check that updates have actually been applied—automatic updates fail more often than expected
- A policy that browsers must be closed and reopened at least once per day to allow updates to finalise
- Monitoring of vendor security advisories (Mozilla, Google, Microsoft) so you’re alerted when emergency patches are released
For businesses with more than 10–15 workstations, consider implementing centralised patch management through tools like Windows Server Update Services (WSUS), Microsoft Intune, or third-party endpoint management platforms that can enforce browser updates across all devices.
Why This Matters More in 2026: AI-Accelerated Vulnerability Discovery
The volume of security patches in 2026 is not a coincidence.
Anthropic’s Mythos AI circumvented macOS security by examining two separate bugs instead of finding a single vulnerability, and Anthropic’s own engineers have cautioned that it is too good at finding security exploits
. AI-driven vulnerability discovery is changing the mathematics of patch management.
As we noted in our recent post on AI-discovered vulnerabilities driving record patch volumes, the security industry is moving from periodic patching to continuous patch-as-you-go programmes.
Apple has announced it now intends to cut the time between discovery of an exploit and the update to address it, with minor security updates now issued as soon as possible rather than held until the next regular release
.
UK SMEs need to adapt to this new environment—or accept that the window of exposure between patch availability and exploitation will only continue to narrow.
What to Do If You’re Not Sure Your Business Can Keep Up
If this Firefox update is the first time you’ve heard about these vulnerabilities, or if you’re not confident every machine in your business is running the latest Firefox version right now, you have a patch management gap.
That gap isn’t unusual—
Vodafone’s Securing Success report found 32% of UK SMEs have no cybersecurity protections whatsoever
—but it is a structural risk that compounds with every new vulnerability cycle.
Consider whether your business would benefit from:
- Managed IT support that monitors vendor security advisories and deploys critical patches as part of a documented schedule
- Centralised endpoint management that gives you visibility into which software versions are running across all devices
- A documented patching SLA that defines how quickly critical, high, and moderate-severity patches are deployed after release
- Quarterly IT security audits that verify patches have been applied and flag machines that have fallen out of compliance
With ransomware attacks continuing to target UK SMEs—323 businesses reported attacks in the 12 months to March 2026—and vulnerability exploitation now the primary attack vector, keeping browsers and other software patched is no longer optional maintenance. It’s core business resilience.
Take Action Today
Mozilla has done its part by releasing Firefox 152.0.6 on 15 July 2026. Public exploit code for CVE-2026-15718 and CVE-2026-15719 is already available, which means the clock is ticking on every unpatched Firefox installation in your business.
Check your Firefox version now, update immediately if required, and use this as a prompt to review whether your business has the patch management processes it needs to keep up with 2026’s accelerated vulnerability disclosure environment.
If you’re a Kent or South East business that needs help implementing structured patch management, endpoint monitoring, or proactive IT security support, Meridian Micro Limited can help. Call us on 01303 883111 or visit our IT support page to discuss how we can help you stay ahead of critical security updates before they become incidents.
