Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Mozilla has released updates to address two critical flaws in Firefox, while Google has shipped fixes for 15 security flaws in Chrome, including two critical use-after-free bugs. Adobe has also published security updates for 88 vulnerabilities, including multiple critical…
Intelligence analysis by Llama

Mozilla and Google have released updates to address critical security flaws in Firefox and Chrome, while Adobe has published security updates for 88 vulnerabilities in various products.
Imagine you're using a browser like Firefox or Chrome, and there's a secret door that hackers can use to get into your computer. Mozilla and Google just fixed this door, so you're safer now. But there are other doors in other software that need to be fixed too, like Adobe's ColdFusion and VMware's Avi Load Balancer. It's like a big game of cybersecurity whack-a-mole – we need to stay on top of these fixes to keep our computers and data safe.
Analysis
A Critical Patch for Firefox and Chrome
Mozilla has released updates to address two critical flaws in Firefox, which have been exploited in the wild. The vulnerabilities, CVE-2026-15718 and CVE-2026-15719, have been patched in Firefox version 152.0.6. The release comes as Google shipped fixes for 15 security flaws, including two critical use-after-free bugs in Ozone (CVE-2026-15764 and CVE-2026-15765).
Adobe's Security Updates
Adobe has published security updates for 88 vulnerabilities, including multiple critical-severity bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. Of these, eight impact Adobe ColdFusion, with CVSS scores ranging from 9.0 to 9.9. The CodeFusion flaws have been remediated in versions ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
VMware's Critical Authentication Bypass Vulnerability
Broadcom has released a fix for a critical authentication bypass vulnerability in VMware Avi Load Balancer (CVE-2026-47865, CVSS score: 9.8). A malicious user with network access can exploit this flaw to access the Avi Control plane. Filip Waeytens of the NATO Cyber Security Centre (NCSC) has been credited with discovering and reporting the flaw.
The Importance of Staying Up-to-Date
Although none of the vulnerabilities have been marked as actively exploited, it's essential that organizations install the latest updates, given that threat actors are known to weaponize flaws in these products in attacks.
Key points
- Mozilla has released updates to address two critical flaws in Firefox.
- Google has shipped fixes for 15 security flaws in Chrome, including two critical use-after-free bugs.
- Adobe has published security updates for 88 vulnerabilities, including multiple critical-severity bugs in ColdFusion, Commerce, Experience Manager, and Illustrator.
- Broadcom has released a fix for a critical authentication bypass vulnerability in VMware Avi Load Balancer (CVE-2026-47865, CVSS score: 9.8).
- Organizations must install the latest updates to prevent potential attacks and keep their systems secure.
If organizations install the latest updates, they can prevent potential attacks and keep their systems secure. This is a positive step towards improving cybersecurity.
However, if organizations fail to install the latest updates, they may be vulnerable to attacks that exploit these critical security flaws. This could lead to significant security breaches and data loss.



