SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16367

CRITICAL · CVSS 10 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A critical vulnerability in Firefox allows for a sandbox escape through an invalid pointer in the Disability Access APIs component, potentially enabling attackers to execute arbitrary code outside of the browser's security confines. Users and organizations relying on Firefox for secure web browsing should prioritize updating to version 153 or later to mitigate this severe risk. This issue poses a significant threat to any environment where Firefox is deployed, particularly in sensitive or high-security contexts.

CVE
CVE-2026-16367
Severity
CRITICAL
CVSS
10
EPSS
0.38%
Firefox

Original NVD Description

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Related CVEs

Other vulnerabilities affecting the same vendor(s)