SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16353

CRITICAL · CVSS 9.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

An invalid pointer vulnerability in the DOM Bindings component of Firefox could allow an attacker to execute arbitrary code, leading to potential system compromise. Users of affected versions, particularly those running Firefox and Thunderbird prior to the specified updates, should prioritize applying the latest patches to mitigate this critical risk. Organizations relying on these applications for web browsing or email should take immediate action to protect their systems.

CVE
CVE-2026-16353
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%
Firefox

Original NVD Description

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Related CVEs

Other vulnerabilities affecting the same vendor(s)