The images in this article were generated with artificial intelligence. How we publish
Mozilla and Google published this week critical patches that correct vulnerabilities that can be exploited to run code or corrupt memory on browsers, and Adobe released a new series of updates that fix dozens of high-gravity failures in server and desktop products. The most urgent news is that Mozilla warned that there is already public explosion code for one of the failures in Firefox, so the risk window for unpatched users has been significantly shortened.
In the case of Firefox, the corrections are included in version 152.0.6 and refer to problems in the JavaScript / WebAssembly engine and in site isolation in the DOM; Mozilla confirmed that there is public operating evidence although, for now, they have not detected targeted attacks in nature. Google, on the other hand, solved 15 Chrome failures, including two critical user--after-free in Ozone - the abstraction layer of inputs and graphics on platforms such as Linux and ChromeOS - that could result in memory corruption if a user makes UI gestures induced by a malicious page.

Adobe reported and patched 88 vulnerabilities in products such as ColdFusion, Commerce, Experience Manager and Illustrator; several of the failures in ColdFusion and on trade platforms have CVSS scores close to 10 and allow from traversal routes and SQL injection to remote code execution without authentication. A Broadcom update was also published for a VMware authentication vulnerability Avi Load Balancer that allows access to the control plane with network access.
The implications for organizations are clear: if you have exposed services - user browsers, ColdFusion servers, trading platforms or balancing - you must act today. The attackers are often quick to take advantage of public exploits and the failures in highly deployed software are preferred for mass campaigns or for post-exploitation in targeted intrusions. In addition, failures in infrastructure components (balers, content managers, ecommerce platforms) can allow for climbing and lateral movement within corporate networks.

If you manage affected assets, prioritize the parking: display Firefox 152.0.6 in endpoints, update Chrome to the versions that correct the reported CVE (the branches 150.7871.124 / .125 according to platform) and apply the Adobe updates for ColdFusion, Commerce and OEM mentioned by the manufacturer. If you cannot park immediately, implement compensatory controls such as restricting access to IP administrative interfaces, placing critical applications behind a Web Application Firewall with rules for armored uploads and SSRF, and segmenting the network to limit the scope of a possible intrusion. Also maintain enhanced detection: review access logs, monitor abnormal behaviors and activate alerts for known operating patterns.
In parallel to the technical response, use this episode to strengthen processes: software inventory and dependencies, exposure-based prioritization and CVSS / business impact, regression tests in controlled environments and fast deployment procedures for hotfixes. Do not forget to coordinate with support and communication equipment to inform end users about the need to update browsers and avoid downloading content or performing unknown gestures on unreliable pages.
To check official security notices and verify versions and mitigation, check the manufacturers' pages and vulnerability databases: Mozilla Security Notices, Adobe Security Centre and the NIST vulnerability database in nvd.nist.gov. Adopting a faster patching cycle and compensatory controls will directly reduce the likelihood that a known failure will be exploited in your environment.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...