AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-13356

MEDIUM · CVSS 6.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

A vulnerability exists in Firefox and Java that allows a malicious webpage to disrupt a pending navigation by queuing a synchronous JavaScript dialog, misleading users by displaying the intended destination in the address bar while rendering attacker-controlled content. This could lead to phishing attacks or other malicious activities, making it crucial for users of affected browsers and Java applications to prioritize updates. Organizations that rely on Firefox for web access should implement the latest security patches to mitigate this risk.

CVE
CVE-2026-13356
Severity
MEDIUM
CVSS
6.3
EPSS
0.13%
Firefox Java

Original NVD Description

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)