CVE-2026-16356 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-16356 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16356 is a use-after-free vulnerability in Mozilla Firefox and Thunderbird Disability Access APIs that can allow a sandbox escape.
Technical Detail
The flaw occurs when the Disability Access APIs component accesses memory after it has been freed. An attacker may be able to trigger the condition through crafted content that causes vulnerable accessibility-related code paths to process invalid object state. Successful exploitation could allow code executing in a restricted sandboxed process to escape browser or application sandbox protections, increasing the impact of further code-execution vulnerabilities.
Exploitation Status
No known exploit has been reported for this vulnerability. CVE-2026-16356 is not listed in CISA's Known Exploited Vulnerabilities catalog as of July 28, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize updates because the vulnerability has a CVSS score of 9.8 and affects sandbox security boundaries. Upgrade Firefox to version 153 or later, Firefox ESR to version 115.38 or 140.13 or later, and Thunderbird to version 153 or Thunderbird 140 or later. No workaround, detection signature, or confirmed exploitation indicator has been published; organizations should verify deployed versions, apply vendor updates through standard software-management processes, and monitor Mozilla security advisories for additional guidance.