T
Threats
Mozilla Firefox Critical Vulnerabilities
Overview
CVE: CVE-2026-16359, CVE-2026-16361, CVE-2026-16394, CVE-2026-16395, CVE-2026-16406, CVE-2026-16408, CVE-2026-16411, CVE-2026-16412
Severity: Critical
Date: 22 July 2026
Excerpt
Mozilla has released security updates addressing eight critical vulnerabilities in Firefox and Firefox ESR. The flaws include memory safety bugs, integer overflows, and mitigation bypasses that could allow an attacker to execute arbitrary code. Secure ISS strongly recommends organisations update affected Firefox installations immediately.
Affected Versions
Firefox prior to version 153
Firefox ESR prior to version 115.38
Firefox ESR prior to version 140.13
Fixed in: Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13
Vulnerability Breakdown
CVE-2026-16359 - Boundary Condition Error
Severity: Critical
CVSS: 9.1
Description: Incorrect boundary conditions were identified in the Audio/Video: GMP component.
Impact: Could allow memory corruption leading to potential code execution.
Conditions: No special privileges required beyond normal browser use.
Notes: Fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
CVE-2026-16361 - Memory Safety Bugs
Severity: Critical
CVSS: 9.8
Description: Memory safety bugs were present in Firefox ESR 115.37 and Firefox ESR 140.12, with evidence of memory corruption.
Impact: Could be exploited to run arbitrary code.
Conditions: No special privileges required.
Notes: Fixed in Firefox ESR 115.38 and Firefox ESR 140.13.
CVE-2026-16394 - Mitigation Bypass
Severity: Critical
CVSS: 9.1
Description: A mitigation bypass was identified in the DOM: Security component.
Impact: Could allow attackers to bypass existing security protections.
Conditions: No special privileges required.
Notes: Fixed in Firefox 153.
CVE-2026-16395 - Integer Overflow
Severity: Critical
CVSS: 9.8
Description: An integer overflow was identified in the Audio/Video component.
Impact: Could lead to memory corruption and potential code execution.
Conditions: No special privileges required.
Notes: Fixed in Firefox 153.
CVE-2026-16406 - Mitigation Bypass
Severity: Critical
CVSS: 9.1
Description: A mitigation bypass was identified in the Networking component.
Impact: Could allow attackers to bypass existing security protections.
Conditions: No special privileges required.
Notes: Fixed in Firefox 153.
CVE-2026-16408 - Integer Overflow
Severity: Critical
CVSS: 9.8
Description: An integer overflow was identified in the Audio/Video: Playback component.
Impact: Could lead to memory corruption and potential code execution.
Conditions: No special privileges required.
Notes: Fixed in Firefox 153.
CVE-2026-16411 - Memory Safety Bugs
Severity: Critical
CVSS: 9.8
Description: Memory safety bugs were present in Firefox 152, with evidence of memory corruption.
Impact: Could be exploited to run arbitrary code.
Conditions: No special privileges required.
Notes: Fixed in Firefox 153.
CVE-2026-16412 - Memory Safety Bugs
Severity: Critical
CVSS: 9.8
Description: Memory safety bugs were present in Firefox ESR 140.12 and Firefox 152, with evidence of memory corruption.
Impact: Could be exploited to run arbitrary code.
Conditions: No special privileges required.
Notes: Fixed in Firefox 153 and Firefox ESR 140.13.
Mitigation
Update Firefox to version 153 or later immediately.
Update Firefox ESR to version 115.38 or 140.13 or later, depending on your ESR branch.
Enable automatic updates where possible to ensure timely patching.
Restart the browser after updating to apply the patch.
Verify update status across all endpoints using centralised device management tools.
Summary for IT Teams
Products: Mozilla Firefox, Firefox ESR
Threat Level: Critical, CVSS up to 9.8
Action Required: Patch all Firefox and Firefox ESR installations to the fixed versions immediately and confirm deployment across the environment.
Reference
Need Help?
Please get in touch on 1300 769 460 or email us. We are here to help you strengthen your cybersecurity posture.

