🚨 CVE-2026-16393
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2045410. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16394
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2046748. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16395
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2047221. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16396
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
🎖@cveNotify
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2047240. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16397
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2047608. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16398
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2048345. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16399
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2049981. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16401
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2052565. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16402
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2052703. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16403
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 1972244. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16404
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2020253. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16405
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
🎖@cveNotify
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2036591. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16406
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2040382. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16407
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2044063. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16408
Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2050477. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16409
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2052134. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16410
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2053680. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
🚨 CVE-2026-16411
Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153.
🎖@cveNotify
🚨 CVE-2026-16412
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
🎖@cveNotify
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
🎖@cveNotify
🚨 CVE-2026-16445
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
🎖@cveNotify
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a temporary shell script without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs during system boot.
🎖@cveNotify
🚨 CVE-2026-59846
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
🎖@cveNotify
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
🎖@cveNotify