
What was published
Mozilla's MFSA 2026-90 advisory identifies Firefox 156 as the fixed release for the issues it covers and assigns the advisory an overall high impact. The listed issues span several browser components.
Mozilla also explains a reporting change: internally identified memory-safety vulnerabilities are now documented individually instead of being grouped into one CVE. A larger number of entries therefore should not automatically be interpreted as an equivalent increase in real-world attacks.
Defensive perspective
Check which Firefox release channel each device uses. Standard Firefox and Extended Support Release have separate advisories and version tracks. Apply the current supported update for that track and verify the browser has restarted into the updated version.
Forensic focus
Record the browser version at collection time and preserve relevant profile artifacts before planned remediation in an active investigation. A security advisory establishes an affected product condition; it does not establish that a particular browsing session was exploited.
Source published 15 September 2026. Briefing prepared 26 September 2026.