CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-16408

    Last Modified: 27 Jul 2026

    Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16407

    Last Modified: 24 Jul 2026

    Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16406

    Last Modified: 27 Jul 2026

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16405

    Last Modified: 22 Jul 2026

    Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    7.4
    High

    CVE-2026-16404

    Last Modified: 27 Jul 2026

    Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

    Published: 21 Jul 2026
    6.5
    Medium

    CVE-2026-16403

    Last Modified: 27 Jul 2026

    Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    8.8
    High

    CVE-2026-16401

    Last Modified: 26 Jul 2026

    Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16402

    Last Modified: 24 Jul 2026

    Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16400

    Last Modified: 27 Jul 2026

    Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16399

    Last Modified: 24 Jul 2026

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16398

    Last Modified: 27 Jul 2026

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    6.5
    Medium

    CVE-2026-16397

    Last Modified: 27 Jul 2026

    Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16395

    Last Modified: 27 Jul 2026

    Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    8.8
    High

    CVE-2026-16396

    Last Modified: 24 Jul 2026

    Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16394

    Last Modified: 27 Jul 2026

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16359

    Last Modified: 22 Jul 2026

    Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16393

    Last Modified: 22 Jul 2026

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16392

    Last Modified: 30 Jul 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16391

    Last Modified: 22 Jul 2026

    Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16390

    Last Modified: 22 Jul 2026

    Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16389

    Last Modified: 24 Jul 2026

    Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16388

    Last Modified: 24 Jul 2026

    Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16387

    Last Modified: 22 Jul 2026

    Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16386

    Last Modified: 24 Jul 2026

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16385

    Last Modified: 24 Jul 2026

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16383

    Last Modified: 22 Jul 2026

    Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16384

    Last Modified: 27 Jul 2026

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16382

    Last Modified: 27 Jul 2026

    Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16381

    Last Modified: 22 Jul 2026

    Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16380

    Last Modified: 27 Jul 2026

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16358

    Last Modified: 22 Jul 2026

    Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    8.8
    High

    CVE-2026-16379

    Last Modified: 24 Jul 2026

    Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16377

    Last Modified: 22 Jul 2026

    Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16378

    Last Modified: 24 Jul 2026

    Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16376

    Last Modified: 27 Jul 2026

    Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16375

    Last Modified: 22 Jul 2026

    Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16374

    Last Modified: 22 Jul 2026

    Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16373

    Last Modified: 27 Jul 2026

    Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

    Published: 21 Jul 2026
    8.8
    High

    CVE-2026-16371

    Last Modified: 1 Sept 2026

    Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, Thunderbird 140.13, Firefox ESR 140.15, and Thunderbird 140.15.

    Published: 21 Jul 2026
    8.8
    High

    CVE-2026-16372

    Last Modified: 26 Jul 2026

    Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.1
    Critical

    CVE-2026-16370

    Last Modified: 22 Jul 2026

    Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16357

    Last Modified: 22 Jul 2026

    Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16356

    Last Modified: 22 Jul 2026

    Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16355

    Last Modified: 22 Jul 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16369

    Last Modified: 22 Jul 2026

    Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16368

    Last Modified: 22 Jul 2026

    Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    10
    Critical

    CVE-2026-16367

    Last Modified: 27 Jul 2026

    Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026
    7.5
    High

    CVE-2026-16354

    Last Modified: 22 Jul 2026

    Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    9.8
    Critical

    CVE-2026-16353

    Last Modified: 22 Jul 2026

    Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

    Published: 21 Jul 2026
    8.8
    High

    CVE-2026-16366

    Last Modified: 24 Jul 2026

    Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

    Published: 21 Jul 2026