01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Critical Firefox Security Update July 2026: Public Exploit Code Released for Two Zero-Day Flaws—What UK SMEs Must Do Today

July 21, 2026 Meridian Micro
Select your web browser(s)

On 15 July 2026, Mozilla released an emergency security update for Firefox addressing two critical vulnerabilities—
CVE-2026-15718 and CVE-2026-15719, with Mozilla confirming that exploit code for both flaws is publicly available
. For UK SMEs running Firefox across employee workstations, this represents an immediate security exposure requiring same-day patching.
With around 150 million people worldwide using Firefox
, the attack surface is substantial, and the availability of working exploit code means the risk moves from theoretical to practical within hours.

This article explains what these vulnerabilities mean for UK businesses, how to verify your Firefox installation is protected, and what patch management steps you should implement today.

What Happened on 15 July 2026: Two Critical Firefox Zero-Day Flaws

Mozilla confirmed that working exploit code for both of Firefox’s critical new vulnerabilities is already publicly available, even though no attacks using that code had been observed in the wild at the time of disclosure
. This is significant because once exploit code becomes public, the window between disclosure and active exploitation typically shrinks from weeks to days—or hours.

The emergency update, Firefox 152.0.6, was released on 15 July 2026 as part of a coordinated security response that also saw Google, Adobe, and VMware issue critical patches on the same day.
Chrome, Adobe ColdFusion, and VMware Avi all delivered urgent patches across browser, application server, and network infrastructure categories, with Mozilla’s Firefox update prioritised first given the confirmed public availability of exploit code
.

Why Public Exploit Code Changes the Risk Profile

The difference between a disclosed vulnerability and a disclosed vulnerability with public exploit code is the difference between a locked door with a publicly known weak lock and a locked door with step-by-step instructions for picking it sitting on the doorstep.

When exploit code becomes public:

Mozilla’s advisory confirms both CVEs have public exploit code, meaning every unpatched Firefox installation is now a known exposure rather than a potential one.

Which Firefox Versions Are Affected?

The vulnerabilities affect all versions of Firefox prior to 152.0.6. This includes:

If your business uses Firefox as a primary or secondary browser, or if staff use Thunderbird for email, both applications require immediate updates.
The vulnerabilities include information disclosure and sandbox escape in Firefox’s Security: Process Sandboxing component, fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12
.

How UK SMEs Should Respond Today

Step 1: Verify Your Firefox Installation Immediately

Open Firefox, click the menu button (three horizontal lines in the top-right corner), select Help, then About Firefox. The version number will display and Firefox will automatically check for updates. If you’re running any version below 152.0.6, install the update immediately and restart the browser.

Do not wait for automatic updates to roll out across your organisation.
A Chrome browser left open continuously may not receive the security fix for days, even after the update has been released
—the same applies to Firefox if users never close and reopen the browser.

Step 2: Check Thunderbird If You Use It for Email

Thunderbird shares Firefox’s rendering engine and is affected by the same vulnerabilities. Open Thunderbird, go to Help > About Thunderbird, and ensure you’re running version 152 or later (or ESR 140.12 or later if you’re on the Extended Support Release channel).

Step 3: Audit Who Uses Firefox Across Your Business

Many UK SMEs run a mixed browser environment—some staff on Chrome, some on Edge, some on Firefox. If your business doesn’t enforce a single browser through Group Policy or mobile device management, you may not know which machines are running Firefox until you check.

This is a good moment to document which browsers are in use across your organisation and whether you have a process for tracking security updates for each one.

Step 4: Implement a Browser Patch Management Process

This is the third major browser vulnerability cycle in July 2026 alone. We recently covered Google Chrome’s 382-vulnerability update and Microsoft’s record-breaking Patch Tuesday with 569 CVEs. The pattern is clear: vulnerability volumes are rising, patch cycles are accelerating, and businesses without structured patch management are falling further behind.

A basic browser patch management process for UK SMEs should include:

For businesses with more than 10–15 workstations, consider implementing centralised patch management through tools like Windows Server Update Services (WSUS), Microsoft Intune, or third-party endpoint management platforms that can enforce browser updates across all devices.

Why This Matters More in 2026: AI-Accelerated Vulnerability Discovery

The volume of security patches in 2026 is not a coincidence.
Anthropic’s Mythos AI circumvented macOS security by examining two separate bugs instead of finding a single vulnerability, and Anthropic’s own engineers have cautioned that it is too good at finding security exploits
. AI-driven vulnerability discovery is changing the mathematics of patch management.

As we noted in our recent post on AI-discovered vulnerabilities driving record patch volumes, the security industry is moving from periodic patching to continuous patch-as-you-go programmes.
Apple has announced it now intends to cut the time between discovery of an exploit and the update to address it, with minor security updates now issued as soon as possible rather than held until the next regular release
.

UK SMEs need to adapt to this new environment—or accept that the window of exposure between patch availability and exploitation will only continue to narrow.

What to Do If You’re Not Sure Your Business Can Keep Up

If this Firefox update is the first time you’ve heard about these vulnerabilities, or if you’re not confident every machine in your business is running the latest Firefox version right now, you have a patch management gap.

That gap isn’t unusual—
Vodafone’s Securing Success report found 32% of UK SMEs have no cybersecurity protections whatsoever
—but it is a structural risk that compounds with every new vulnerability cycle.

Consider whether your business would benefit from:

With ransomware attacks continuing to target UK SMEs—323 businesses reported attacks in the 12 months to March 2026—and vulnerability exploitation now the primary attack vector, keeping browsers and other software patched is no longer optional maintenance. It’s core business resilience.

Take Action Today

Mozilla has done its part by releasing Firefox 152.0.6 on 15 July 2026. Public exploit code for CVE-2026-15718 and CVE-2026-15719 is already available, which means the clock is ticking on every unpatched Firefox installation in your business.

Check your Firefox version now, update immediately if required, and use this as a prompt to review whether your business has the patch management processes it needs to keep up with 2026’s accelerated vulnerability disclosure environment.

If you’re a Kent or South East business that needs help implementing structured patch management, endpoint monitoring, or proactive IT security support, Meridian Micro Limited can help. Call us on 01303 883111 or visit our IT support page to discuss how we can help you stay ahead of critical security updates before they become incidents.