CVE-2026-16363 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-16363 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16363 is a JIT miscompilation vulnerability in the JavaScript: WebAssembly component of Mozilla Firefox and Mozilla Thunderbird.
Technical Detail
The flaw occurs when the JavaScript and WebAssembly just-in-time compiler incorrectly compiles certain attacker-controlled code. An attacker could trigger the issue by causing a vulnerable application to process malicious JavaScript or WebAssembly content, such as through web content. Successful exploitation could allow arbitrary code execution in the context of the affected Firefox or Thunderbird process.
Exploitation Status
No known exploit has been reported for this vulnerability. CVE-2026-16363 is not listed in CISA's Known Exploited Vulnerabilities catalog as of July 28, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Update Firefox to version 153 or later, Firefox ESR to version 140.13 or later, Thunderbird to version 153 or later, and Thunderbird ESR to version 140.13 or later. Organizations should prioritize deployment because the issue has a Critical CVSS score of 9.8 and affects content-processing components. No workaround or reliable exploitation-specific detection signal has been published; verify patch deployment through software inventory, endpoint management, or version telemetry.