SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16412

CRITICAL · CVSS 9.8 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Firefox and Firefox ESR versions 140.12 and 152 contain critical memory safety vulnerabilities that could potentially allow attackers to execute arbitrary code through memory corruption. Organizations using these affected versions should prioritize updating to Firefox 153 or Firefox ESR 140.13 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16412
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%
Firefox

Original NVD Description

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Related CVEs

Other vulnerabilities affecting the same vendor(s)