Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-16361 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-16361 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-16361 is a set of memory safety vulnerabilities affecting Mozilla Firefox and Thunderbird, with the available technical description specifically identifying Thunderbird ESR 140.12; the affected components and exact attack surface have not been specified.

Technical Detail

The flaws involve memory safety bugs, some of which showed evidence of memory corruption. The available information does not identify the precise trigger conditions or vulnerable code paths. Mozilla assesses that, with sufficient exploitation effort, some of these issues could potentially permit arbitrary code execution in the context of the affected application.

Exploitation Status

No known exploit has been reported, and CVE-2026-16361 is not listed in CISA's Known Exploited Vulnerabilities Catalog as of July 28, 2026.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Apply Mozilla security updates for Firefox and Thunderbird immediately, with priority given to systems running Thunderbird ESR 140.12. Verify deployed versions against Mozilla's applicable security advisories and update channels, as fixed-version information is not included in the available data. No workaround or reliable detection indicators have been published; security teams should monitor endpoint telemetry and application crash reports for unexpected Firefox or Thunderbird failures that may indicate attempted exploitation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →