Mozilla Firefox Security Update – 18 February 2026

Mozilla has released an updated Firefox version 147.0.4, Firefox ESR versions 140.7.1 and 115.32.1 to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the attacker to perform denial of service attacks, execute arbitrary code, and gain access to the affected system.

Mozilla Firefox Heap Buffer Overflow Vulnerability in Libvpx (CVE-2026-2447):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Denial of Service
Vulnerabilities

CVE-2026-2447

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References