Mozilla Firefox Security Update – 14 May 2026

Mozilla has released an updated Firefox version 150.0.3 to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the attacker to conduct denial-of-service attacks, bypass security restrictions, or execute arbitrary code and gain access to the affected system.

Sample of the addressed vulnerabilities:

Mozilla Firefox Use-After-Free in the JavaScript: WebAssembly Component (CVE- 2026-8390):

  • CVSS: 7.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2026-8388
  • CVE-2026-8389
  • CVE-2026-8390
  • CVE-2026-8391
  • CVE-2026-8401
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox Security Advisory

References