Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-16367 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-16367 | CVSS 10.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-16367 is a critical sandbox escape vulnerability in Mozilla Firefox and Mozilla Thunderbird involving an invalid pointer in the Disability Access APIs component.

Technical Detail

The flaw arises from invalid pointer handling within the Disability Access APIs component. An attacker may be able to trigger the issue through crafted web content or content processed by the affected applications, potentially escaping the browser or mail client sandbox. Successful exploitation could allow code execution outside the intended sandbox boundary, increasing the impact of a separate in-browser or application-level compromise.

Exploitation Status

No known exploit has been reported for this vulnerability. CVE-2026-16367 is not listed in CISA's Known Exploited Vulnerabilities Catalog as of July 28, 2026.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Update Firefox and Thunderbird to version 153 or later, which includes the vendor fix. Prioritize remediation on systems that routinely access untrusted websites, email content, attachments, or links. No workaround, specific detection signature, or confirmed exploitation activity has been published; organizations should monitor Mozilla security advisories and endpoint telemetry for unusual child-process behavior or unexpected code execution originating from Firefox or Thunderbird.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →