Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-16349 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-16349 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-16349 is a same-origin policy bypass in the DOM Navigation component affecting Mozilla Firefox and Mozilla Thunderbird.

Technical Detail

The flaw allows a malicious webpage to bypass same-origin restrictions through DOM navigation behavior. An attacker could trigger the issue by convincing a user to open or interact with crafted web content, potentially allowing unauthorized cross-origin access to data or content that should be isolated by the browser security model. The available information does not confirm remote code execution, privilege escalation, or authentication bypass.

Exploitation Status

No known exploit has been reported as of July 28, 2026. CVE-2026-16349 is not listed in CISA's Known Exploited Vulnerabilities Catalog.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize updates to Firefox 153 or later, Firefox ESR 115.38 or later, Firefox ESR 140.13 or later, Thunderbird 153 or later, and Thunderbird 140.13 or later. Organizations should use supported Firefox ESR and Thunderbird release channels, verify deployed versions after patching, and restrict access to untrusted websites where immediate updates are not possible. No vendor-supported workaround or specific detection indicator is currently confirmed.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →