CyberSecurity

Patch Tuesday in Miniature: Firefox, Chrome, Adobe, and VMware Rush Out Critical Fixes

Published

on

Mozilla’s Urgent Warning: Two Critical Flaws, Public Exploit Code

Mozilla didn’t hedge. The organization pushed out updates for Firefox on Wednesday, addressing two critical vulnerabilities — and it explicitly warned that exploit code for both is already circulating in the wild. That’s not the usual vague advisory language. That’s a “patch now” signal.

The first flaw, tracked as CVE-2026-15718, is an invalid pointer issue in the JavaScript: WebAssembly component. The second, CVE-2026-15719, involves a site isolation bypass in the DOM: Navigation component. Both are rated critical, and both have public exploit code. Mozilla’s advisory notes that it is not aware of active exploitation in the wild yet, but with proof-of-concept code out there, the gap between “public” and “exploited” tends to shrink fast.

Firefox users should update to the latest version immediately. The fix is included in Firefox 138.0.1 and Firefox ESR 128.4.1. If you’re still on an older ESR channel, check Mozilla’s release notes — some extended support branches received backported patches.

Chrome’s Turn: A Heap Overflow in the V8 Engine

Google followed suit with its own critical advisory. The Chrome team patched CVE-2026-15724, a heap overflow vulnerability in the V8 JavaScript engine. Heap overflows in V8 have historically been a favorite target for attackers, often leading to remote code execution. Google’s threat intelligence partners flagged the bug, and the company has already rolled out the fix in Chrome 138.0.7204.110 for Windows and macOS, and 138.0.7204.111 for Linux.

The stable channel update is being staged over the coming days, so if your browser hasn’t auto-updated yet, it will soon. You can also force it: click the three-dot menu, go to Help, then About Google Chrome. That triggers an immediate update check. A quick reboot of the browser after the update is a good habit.

Adobe Acrobat and Reader: Critical Flaws Across the Board

Adobe’s April security bulletin is a hefty one. The company patched multiple critical vulnerabilities in Adobe Acrobat and Reader, affecting both Windows and macOS. The most serious issues could allow an attacker to execute arbitrary code with the privileges of the logged-in user — which is to say, if you open a malicious PDF, your system is at risk.

Among the patched CVEs are CVE-2026-15731 and CVE-2026-15732, both use-after-free vulnerabilities. Adobe also fixed several out-of-bounds write issues, including CVE-2026-15735 and CVE-2026-15736. The updates are available for Acrobat DC (Continuous Track) version 26.001.20210 and Acrobat Reader DC version 26.001.20210. For those on the Classic Track, versions 24.005.20416 and 22.003.23227 include the fixes.

Adobe hasn’t reported any active exploits for these flaws, but given the history of PDF-based attacks, treating this update as urgent is the smart move. The company rates all of these as critical severity.

VMware: ESXi, Workstation, and Fusion Patched for Memory Corruption

VMware closed out the week with its own advisory, addressing a critical vulnerability in its hypervisor products. The flaw, CVE-2026-15740, is a memory corruption issue in the virtual machine display unit (VMU) that could allow a malicious actor with local administrative privileges on a virtual machine to execute code as the host’s kernel. In plain terms: an attacker who compromises a guest VM could potentially break out and take over the entire host server.

Patches are available for VMware ESXi 8.0 (update 3b), ESXi 7.0 (update 3u), Workstation Pro 17.x, and Fusion 13.x. There are no workarounds for this issue, so applying the update is the only mitigation. VMware’s advisory emphasizes that the vulnerability requires local admin access to the VM, which lowers the immediate risk slightly — but in multi-tenant environments or shared infrastructure, that’s cold comfort.

What Should You Do Right Now?

Here’s a practical checklist to get your systems patched:

  • Firefox: Update to Firefox 138.0.1 or ESR 128.4.1. Check via the menu → Help → About Firefox.
  • Chrome: Ensure you’re on 138.0.7204.110 or later. Restart the browser after updating.
  • Acrobat/Reader: Install version 26.001.20210 (Continuous) or the corresponding Classic Track update. Use Help → Check for Updates within the application.
  • VMware: Apply the ESXi, Workstation, or Fusion patches listed in VMSA-2026-0012. No workaround exists.

For enterprises, prioritize the VMware ESXi patches first, especially if you run multi-tenant workloads. The guest-to-host breakout potential is the kind of thing that keeps infrastructure teams up at night. Next, push the Firefox and Chrome updates to all endpoints — browser-based attacks are the most common initial access vector in breaches. Adobe Acrobat should follow, particularly for finance, legal, and HR teams that handle PDFs daily.

For more on securing your browsers, check out our guide on hardening browser security settings and best practices for enterprise patch management strategies.

This round of updates is a reminder that the patch cycle never sleeps. Four major vendors, multiple critical flaws, and at least one instance of public exploit code. The window to act is now.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version