CVE-2026-16370 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-16370 | CVSS 9.1 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16370 is a mitigation-bypass vulnerability in Mozilla Firefox and Mozilla Thunderbird affecting the DOM: Networking component.
Technical Detail
The flaw allows a security mitigation in the DOM networking implementation to be bypassed under conditions not publicly detailed in the available advisory information. An attacker would need to cause the affected application to process attacker-controlled web or network content through the vulnerable component. The resulting security impact, including whether the bypass enables code execution, information disclosure, or another downstream condition, has not been publicly confirmed.
Exploitation Status
No known exploit has been reported, and CVE-2026-16370 is not listed in CISA's Known Exploited Vulnerabilities catalog as of July 28, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize updates to Firefox 153 or later and Thunderbird 153 or later, which contain the fix for this vulnerability. Organizations should verify deployed browser and email-client versions across managed endpoints, including systems that may defer application updates. No vendor-supported workaround or specific detection indicator has been publicly identified; monitor Mozilla security advisories for additional technical details and any subsequent exploitation reporting.