2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16393 — Incorrect: boundary conditions in the Graphics: WebGPU component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16393

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.1 (CRITICAL)

CWECWE 119TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16392 — JIT: miscompilation in the JavaScript Engine: JIT component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16392

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. CVSSv3.1 9.1 (CRITICAL) · EPSS 5th percentile

CWECWE 843CWECWE 670VNDJitTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16390 — Mitigation: bypass in the Enterprise Policies component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16390

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.1 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16389 — Incorrect: boundary conditions, integer overflow in the Libraries component in NSS.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16389

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16388 — Sandbox: escape in the DOM: Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16388

Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16387 — Site: isolation issue in the Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16387

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284CWECWE 200CWECWE 346TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16383 — Mitigation: bypass in the DOM: Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16383

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16382 — Mitigation: bypass in the DOM: Service Workers component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16382

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16381 — Same: Same-origin policy bypass in the Networking: DNS component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16381

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.1 (CRITICAL)

CWECWE 346TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16380 — Mitigation: bypass in the Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16380

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.1 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16379 — Privilege: escalation in the DOM: Content Processes component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16379

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16377 — Mitigation: bypass in the PDF Viewer component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16377

Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16375 — Site: isolation issue in the Networking: HTTP component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16375

Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 346TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16372 — Privilege: escalation in the DOM: Content Processes component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16372

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16371 — Privilege: escalation in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16370 — Mitigation: bypass in the DOM: Networking component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16370

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.1 (CRITICAL)

CWECWE 693VNDMitigationTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16369 — Integer: overflow in the JavaScript: WebAssembly component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16369

Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16368 — Incorrect: boundary conditions in the JavaScript: WebAssembly component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16368

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16367 — Sandbox: escape due to invalid pointer in the Disability Access APIs component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16367

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153. CVSSv3.1 10.0 (CRITICAL)

CWECWE 416CWECWE 787CWECWE 119TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16366 — Privilege: escalation in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16365 — Privilege: escalation in the DOM: Workers component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16364 — Incorrect: boundary conditions in the Audio/Video: Playback component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16364

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153. CVSSv3.1 9.1 (CRITICAL)

CWECWE 120CWECWE 119TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16363 — JIT: miscompilation in the JavaScript: WebAssembly component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16363

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 843CWECWE 682VNDJitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 13:17Z
HIGH

CVE-2026-16362 — Use: Use-after-free in the WebRTC: Audio/Video component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16362

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 13:17Z
CRIT

CVE-2026-16361 — Memory: Some of these bugs showed evidence of memory corruption and we presume that with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16361

Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38 and Firefox ESR 140.13. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score