CVE-2026-16359 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-16359 | CVSS 9.1 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16359 is an incorrect boundary conditions vulnerability in Mozilla Firefox and Thunderbird’s Audio/Video: GMP component, which processes supported media-related content.
Technical Detail
The flaw results from improper handling of boundary conditions within the GMP component. An attacker may be able to trigger the issue by causing an affected application to process crafted content through the vulnerable media component. The available advisory does not specify the exact security primitive or confirm whether successful exploitation results in remote code execution, but Mozilla has assigned the issue a Critical CVSS score of 9.1.
Exploitation Status
No known exploit has been reported as of July 28, 2026. This CVE is not listed in CISA’s Known Exploited Vulnerabilities Catalog, and there is no public proof-of-concept or operational exploit information in the available data.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize updates to Firefox 153 or later, Firefox ESR 115.38 or later, Firefox ESR 140.13 or later, Thunderbird 153 or later, and Thunderbird 140.13 or later. Organizations should use centralized software inventory and endpoint-management tools to identify systems running earlier versions and verify successful deployment of the applicable update. No vendor-supported workaround, specific detection signature, or confirmed exploitation indicator is available in the provided information; monitor Mozilla security advisories and endpoint telemetry for abnormal application crashes or media-processing failures pending further technical disclosure.