Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-16351 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-16351 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-16351 is a use-after-free sandbox escape vulnerability in the DOM Navigation component of Mozilla Firefox and Mozilla Thunderbird.

Technical Detail

The flaw results from unsafe handling of an object after its memory has been freed within the DOM Navigation component. An attacker could trigger the condition by causing a victim to process attacker-controlled web content, potentially allowing code execution outside the browser or mail client content sandbox. Successful exploitation could enable remote code execution in the context of the affected application and reduce the protection provided by Mozilla's sandboxing architecture.

Exploitation Status

No known exploit has been reported, and CVE-2026-16351 is not listed in CISA's Known Exploited Vulnerabilities catalog as of July 28, 2026.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Apply Mozilla security updates as a high priority. Upgrade Firefox to version 153 or later, Firefox ESR to version 115.38 or 140.13 or later within their respective release branches, and Thunderbird to version 153 or Thunderbird ESR 140.13 or later. No workaround or specific detection indicators have been provided; organizations should verify installed versions across managed endpoints and restrict use of unsupported Firefox and Thunderbird releases.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →