Firefox 157 (MFSA 2026-97, 29 Sep): ~76 fixes incl. high sandbox escapes / UAF; ESR companion trains
Mozilla MFSA 2026-97 (announced 29 September 2026) — Security Vulnerabilities fixed in Firefox 157. Large advisory set (Mozilla now issues per-bug CVEs): high-impact items include sandbox escapes and use-after-free across DOM/Content Processes, Graphics/WebGPU, WebAssembly, Widget, and related components (examples: CVE-2026-100758, 100760, 100762, 100770, 100775, 100778, 100781, 100786, 100787). SecurityWeek 30 Sep roundup cites ~76 issues with ~38 high-severity in Firefox 157, with many also fixed in Firefox ESR 153.4 / 140.17 / 115.42 (MFSA 2026-99 / 2026-100 trains). No in-the-wild exploitation stated in the MFSA. Chrome 154.0.8037.92/.93 companion already on desk as chrome-154-20260922. Primary: Mozilla MFSA 2026-97; wire: SecurityWeek 30 Sep.
- Product
- Mozilla Firefox / Firefox ESR
- Versions
- Fixed in Firefox 157; many issues also in ESR 153.4 / 140.17 / 115.42 (see MFSA 2026-99 / 2026-100).
- Exploited in Australia?
- unknown
- Patch to
- Update to Firefox 157 (or latest ESR 153.4 / 140.17 / 115.42 for ESR channels).
Primary: Mozilla — MFSA 2026-97 Firefox 157 (29 Sep 2026) · Vendor: Mozilla security advisories · CVE: CVE-2026-100758 · SecurityWeek — Chrome + Firefox 100+ vulns (30 Sep 2026)
