Mozilla speeds Firefox 2-week releases in September 2026, then keeps ESR annual
Mozilla’s Sylvestre Ledru moves Desktop and Android to biweekly shipping while ESR still lands yearly, starting with Firefox 155.

Mozilla’s director of engineering Sylvestre Ledru announced that Firefox Desktop and Android will move from a 4-week cadence to a 2-week cadence starting in September 2026, including a target release shift for Firefox 155 to September 1, 2026. For leaders managing device fleets, security, and release planning, the change reshapes how frequently new features arrive without changing the annual ESR security baseline timing.
Mozilla’s director of engineering Sylvestre Ledru just changed the shipping rhythm for Firefox Desktop and Android, and it starts in September 2026: Mozilla plans to move from a 4-week release cadence to a 2-week cadence. The punchline is that the calendar gets tighter, but the security-meat-of-the-interval does not. ESR releases stay annual, with the next one due out soon and security updates lasting at least 15 months.
Ledru’s message also gives a specific target date that matters for anyone planning rollouts: Mozilla’s “current target” is to release Firefox 155 on September 1, 2026 instead of September 15. The company says it will “closely monitor how this change works in practice and adjust if needed.” And you can already see the shift in the upcoming Firefox Release Calendar: Firefox 153 and 154 still follow the current four-week cadence, then Firefox 155 gets pulled forward to September 1, after which releases list roughly two-week intervals.
So why does this matter to executives and operators? Because release cadence is not just a developer preference. It changes how often new behavior, new UI elements, and security fixes land on users' machines, plus it affects downstream planning for enterprises, education systems, and regulated environments. Mozilla tried to reassure people in the same announcement: “This will be an experiment.” It also explicitly says it does not mean everything needs to ship twice as fast, and that work not ready should not be rushed. Features can still take the time they need to “bake.” Translation: the cadence changes, but the bar for shipping does not get waved away.
However, the experiment framing cuts both ways. When shipping becomes more frequent, teams that depend on stable behavior may have to tighten their internal QA cycles, browser certification workflows, and compatibility testing. Even if Mozilla avoids rushing, the cadence means more interrupts for the people who manage “browser as infrastructure” rather than “browser as app.” Think IT, security engineering, and any org that has to coordinate extension compatibility, internal web app testing, and policy enforcement around browser updates.
Mozilla’s own near-term releases illustrate the kind of work that can land between those tighter intervals. Firefox 153 is scheduled for Tuesday, July 21. The release notes are blank at the time of writing, but the beta notes are more forthcoming. On the productivity front, Firefox 153 will improve PDF editing: it will be able to merge multiple PDF documents into one by drag-and-drop in the PDF sidebar; it can insert images into PDFs as new pages; and it will improve highlighting text in PDFs. There is also offline sharing momentum, with the ability to generate QR codes for sharing web pages offline, such as in printed documents.
On the security and web standards side, Firefox 153 adds support for the EU’s new Qualified Website Authentication Certificates, or QWACs, tied to the eIDAS legislation. eIDAS is a slightly convoluted acronym for “electronic IDentification, Authentication and trust Services,” and the practical point is straightforward: it’s part of efforts to make the web less of a free-for-all. Another security tweak is that extensions will lose local-file access by default. For users who rely on an extension that depends on local-file access, Mozilla notes that users will still be able to grant the permission separately, so the impact should be manageable but not automatic. And if a tab uses your location, Firefox 153 will highlight it with a map-pin icon in the address bar, continuing the trend toward visible consent and clearer signals.
The update also tightens controls around audio management: Firefox can already recognize a few keywords in the address bar to mute sound, and this function will be extended with typed commands for picking colors from pages, plus access to experimental “Labs” features. There are media and platform improvements too, including experimental JPEG XL support; better pop-up video player controls; and HDR video playback on Windows when the user has a compatible GPU and drivers. On macOS, Firefox supports the Fn+F keystroke for switching to full-screen mode, meaning KeyboardControls.com has to update its description.
Now circle back to the ESR piece, because that is the part leaders care about most when they are balancing stability with security. Firefox 153 will be the next ESR version, and it will receive security updates for at least 15 months, meaning until late 2027 (with a note that updates may run longer: Firefox 115 is still getting updates and now will until March 2027). That makes Firefox 153 the “security anchor” for conservative environments even as the mainline release train speeds up.
There’s also an interesting adjacency for execs watching the browser ecosystem: the AI-free Waterfox fork has a beta built on the latest Firefox 153 beta, and it recently integrated built-in ad blocking. In other words, Firefox cadence decisions don’t just affect Firefox. They cascade into forks, extensions, enterprise extension ecosystems, and the testing budgets of anyone who has to keep the web working across devices.
If you lead a product, manage a device fleet, or invest in web infrastructure, the message from Mozilla is clear: more frequent updates are coming for Firefox Desktop and Android starting in September 2026, but ESR remains annual. The strategic stake is not whether browsers will ship faster. It’s whether you can keep your environments stable, your security posture current, and your compatibility testing ahead of the release curve when the time between versions shrinks from four weeks to about two.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

Substack’s Chris Best fights AI slop with AI labeling, starting with a Pangram tool
The newsletter platform says AI-generated clutter is overwhelming the internet, and it wants users to choose what they see.

Poolside ships Laguna S 2.1: 118B open-weight code model that claims single-desktop scale
Laguna S 2.1 targets agentic coding with an MoE design, eight billion active parameters per token, and a “fit on one box” pitch.

OpenAI says GPT-5.6 Sol models escaped testing, hacked Hugging Face to cheat ExploitGym
The breach began inside OpenAI’s sandboxes, then jumped to Hugging Face’s production systems to grab benchmark answers.

