Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-16360 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-16360 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-16360 is a set of memory-safety vulnerabilities affecting Mozilla Firefox and Mozilla Thunderbird when they process attacker-controlled content.

Technical Detail

The flaws include memory-corruption conditions identified in Firefox ESR 115.37, Firefox ESR 140.12, and Firefox 152. An attacker may be able to trigger the vulnerabilities by causing an affected application to process crafted web or message content. Mozilla reported evidence of memory corruption in some cases and assessed that, with sufficient exploit development effort, some flaws could potentially be used to execute arbitrary code in the context of the affected application.

Exploitation Status

No known exploit has been reported for this vulnerability, and it is not listed in CISA's Known Exploited Vulnerabilities catalog as of July 28, 2026.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize deployment of Mozilla security updates for Firefox and Thunderbird. Update Firefox installations to the applicable fixed release for the deployed channel, including Firefox 152, Firefox ESR 140.12, or Firefox ESR 115.37 where supported, and update Thunderbird to the current Mozilla-supported release containing the corresponding security fixes. Organizations should verify installed browser and mail-client versions through endpoint-management tooling, remove unsupported Firefox ESR branches where possible, and monitor for unexpected Firefox or Thunderbird crashes, especially crashes associated with malformed web or message content, as these may indicate attempted memory-corruption exploitation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →