Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component - CVE-2026-15719, a site isolation in the DOM: Navigation component "We are aware that exploit code for this is public, however we are not aware of any attacks in the wild abusing this flaw," Mozilla said in an advisory. Both vulnerabilities have been addressed in Firefox version 152.0.6. The release comes as Google shipped fixes for 15 security flaws, including two critical use-after-free bugs in Ozone (CVE-2026-15764 and CVE-2026-15765), a cross-platform abstraction layer that allows the browser to interact natively with various display servers and windowing systems. It supports Linux, ChromeOS, and Fuchsia. "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page," according to a description of CVE-2026-15764 in the NIST National Vulnerability Database (NVD). The shortcomings have been patched in Chrome version 150.0.7871.124/.125 for Windows and Mac and 150.0.7871.124 for Linux. In a related development, Adobe has published security updates for 88 vulnerabilities, including multiple critical-severity bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. Of these, eight impact Adobe ColdFusion - - CVE-2026-48318 (CVSS score: 9.9) - A path traversal vulnerability that could lead to arbitrary code execution - CVE-2026-48322 (CVSS score: 9.6) - A code injection vulnerability that could lead to arbitrary code execution - CVE-2026-48284 (CVSS score: 9.6) - An improper input validation vulnerability that could lead to arbitrary code execution - CVE-2026-48321 (CVSS score: 9.3) - An incorrect authorization vulnerability that could lead to privilege escalation - CVE-2026-48325 (CVSS score: 9.3)