Particle.news
Download on the App Store

Browsers and Enterprise Software Receive Urgent Patches for Multiple Critical Flaws

Public exploit code for two Firefox defects elevates short-term risk, prompting immediate patching.

Overview

  • Mozilla released Firefox 152.0.6 to fix two critical flaws tracked as CVE-2026-15718 and CVE-2026-15719, which affect WebAssembly pointer handling and site-isolation in DOM navigation.
  • Google rolled out Chrome 150 builds (150.0.7871.124/.125) that fix 15 vulnerabilities, including two critical use-after-free bugs in the Ozone layer that can be triggered by crafted pages and specific UI gestures on Linux.
  • Adobe pushed security updates covering 88 flaws across ColdFusion, Commerce, Experience Manager, and Illustrator, with several ColdFusion bugs scoring in the 9.x range and enabling remote code execution or privilege escalation.
  • Broadcom/VMware issued a patch for a critical authentication-bypass in VMware Avi Load Balancer (CVE-2026-47865, CVSS 9.8) that could let an attacker with network access reach the Avi control plane.
  • Security advisories and NVD entries describe concrete exploit paths and public proof-of-concept code for the Firefox issues, so organizations and users should install vendor updates, restart affected systems, and verify versions without delay.