SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16361

CRITICAL · CVSS 9.8 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Memory safety vulnerabilities in Firefox could allow attackers to exploit memory corruption issues, potentially leading to arbitrary code execution. Organizations using affected versions of Firefox and Thunderbird, particularly those handling sensitive data, should prioritize patching to mitigate the risk of exploitation. Immediate updates to Firefox ESR 115.38, Firefox ESR 140.13, or Thunderbird 140.13 are essential to ensure security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16361
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%
Firefox

Original NVD Description

Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.

Related CVEs

Other vulnerabilities affecting the same vendor(s)