Mozilla Foundation Security Advisory 2026-10

Security Vulnerabilities fixed in 147.0.4, ESR 140.7.1, and ESR 115.32.1

Announced
February 16, 2026
Impact
high
Products
Firefox, Firefox ESR
Fixed in
  • Firefox 147.0.4
  • Firefox ESR 115.32.1
  • Firefox ESR 140.7.1

#CVE-2026-2447: Heap buffer overflow in libvpx

Reporter
jayjayjazz
Impact
high
References