CVE-2026-16360
Firefox users on older versions may be vulnerable to a memory corruption bug that could let attackers run code on their computers. The issue has been fixed in newer releases of Firefox and Thunderbird. Updating to the latest version protects against this risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Firefox ESR 115.37, Firefox ESR 140.12, Firefox 152, Thunderbird 153, Thunderbird 140.13 users running those specific versions. Typical users of these browsers on Windows, macOS, or Linux are at risk.
Real-world impact
An attacker could potentially execute arbitrary code on the victim’s machine, taking full control of the system, stealing data, or installing malware.
Why this severity
The CVSS score is high because the vulnerability can be exploited remotely without any user interaction, and it allows attackers to modify the system, read or delete data, and gain full control.
What to do about it
- 011. Update Firefox to version 153 or later, or to Firefox ESR 115.38 or ESR 140.13.
- 022. Update Thunderbird to version 153 or later, or to Thunderbird ESR 140.13.
NVD-referenced vendor advisory
Timeline
- Jul 21, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 24, 2026 · 9d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- bugzilla.mozilla.org/buglist.cgibroken link
- bugzilla.mozilla.org/buglist.cgipermissions required
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory