Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefox, while Adobe fixed numerous critical flaws in its Creative Cloud suite. VMware also released a fix for a critical authentication bypass in its Avi Load Balancer, highlighting the ongoing need for organizations to promptly update their systems to mitigate potential exploitation.
Mozilla has released updates to address two critical flaws in Firefox, with exploit code already in the wild. These vulnerabilities, CVE-2026-15718 and CVE-2026-15719, affect the WebAssembly and DOM Navigation components, respectively. The update comes as Google has also released fixes for 15 security flaws in Chrome, including two critical use-after-free bugs in Ozone. Adobe has published security updates for 88 vulnerabilities across its Creative Cloud suite, including multiple critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. These Adobe flaws include a path traversal vulnerability in ColdFusion (CVE-2026-48318) and a file upload vulnerability in Adobe Commerce (CVE-2026-48356). Additionally, Broadcom has released a fix for a critical authentication bypass vulnerability in VMware Avi Load Balancer (CVE-2026-47865), discovered and reported by the NATO Cyber Security Centre (NCSC). Despite the lack of active exploitation reports, organizations are strongly advised to install the latest updates to prevent potential attacks.
