CVE-2026-16360 – Firefox

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“Every unpatched memory bug is a door left ajar — attackers only need one to walk through.”

Mozilla has patched three Critical memory safety flaws in Firefox. CVE-2026-16411 has a CVSS score of 9.8, Critical severity, and affects Firefox 152. CVE-2026-16412 has a CVSS score of 9.8, Critical severity, and affects Firefox ESR 140.12 and Firefox 152. CVE-2026-16360 has a CVSS score of 9.8, Critical severity, and affects Firefox ESR 115.37, Firefox ESR 140.12, and Firefox 152. All three stem from memory corruption bugs that could, with enough effort, be exploited to run arbitrary code.

The fixes ship in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. Update all affected Firefox and Thunderbird installations to the patched versions without delay.

Key Details

Affected Product
Mozilla Firefox
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-119
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.