Mozilla Firefox Security Updates – 08 April 2026

Mozilla has released an updated Firefox version 149.0.2, Firefox ESR versions 115.34.1 and 140.9.1 to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and corrupt memory that could lead to full compromise of the affected system.

Sample of the addressed vulnerabilities:

Mozilla Firefox and Firefox ESR Memory Safety Bugs Vulnerability (CVE-2026- 5731):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Remote Code Execution
Vulnerabilities
  • CVE-2026-5731
  • CVE-2026-5732
  • CVE-2026-5733
  • CVE-2026-5734
  • CVE-2026-5735
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References