Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-16355 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-16355 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-16355 is a JIT miscompilation vulnerability in the JavaScript Engine JIT component used by Mozilla Firefox and Mozilla Thunderbird.

Technical Detail

The flaw occurs when the JavaScript just-in-time compiler generates incorrect machine code while processing crafted JavaScript. An attacker could trigger the issue by causing the affected application to process malicious JavaScript content. Successful exploitation could allow arbitrary code execution in the security context of the affected application.

Exploitation Status

No known exploit has been reported, and this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Public proof-of-concept exploit availability has not been confirmed.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize updates for systems running Mozilla Firefox or Thunderbird. Upgrade Firefox to version 153, Firefox ESR to version 115.38 or 140.13, Thunderbird to version 153, or Thunderbird ESR to version 140.13, as applicable. Until updates are deployed, limit use of affected applications for untrusted web or JavaScript content where operationally feasible. No vendor-supported workaround, exploitation indicators, or detection signatures have been confirmed in the available data.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →