T

Threats

Mozilla Firefox Critical Vulnerabilities

Overview

CVE: CVE-2026-16359, CVE-2026-16361, CVE-2026-16394, CVE-2026-16395, CVE-2026-16406, CVE-2026-16408, CVE-2026-16411, CVE-2026-16412

Severity: Critical

Date: 22 July 2026


Excerpt

Mozilla has released security updates addressing eight critical vulnerabilities in Firefox and Firefox ESR. The flaws include memory safety bugs, integer overflows, and mitigation bypasses that could allow an attacker to execute arbitrary code. Secure ISS strongly recommends organisations update affected Firefox installations immediately.


Affected Versions

  • Firefox prior to version 153

  • Firefox ESR prior to version 115.38

  • Firefox ESR prior to version 140.13

Fixed in: Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13


Vulnerability Breakdown

CVE-2026-16359 - Boundary Condition Error

Severity: Critical

CVSS: 9.1

Description: Incorrect boundary conditions were identified in the Audio/Video: GMP component.

Impact: Could allow memory corruption leading to potential code execution.

Conditions: No special privileges required beyond normal browser use.

Notes: Fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

CVE-2026-16361 - Memory Safety Bugs

Severity: Critical

CVSS: 9.8

Description: Memory safety bugs were present in Firefox ESR 115.37 and Firefox ESR 140.12, with evidence of memory corruption.

Impact: Could be exploited to run arbitrary code.

Conditions: No special privileges required.

Notes: Fixed in Firefox ESR 115.38 and Firefox ESR 140.13.

CVE-2026-16394 - Mitigation Bypass

Severity: Critical

CVSS: 9.1

Description: A mitigation bypass was identified in the DOM: Security component.

Impact: Could allow attackers to bypass existing security protections.

Conditions: No special privileges required.

Notes: Fixed in Firefox 153.

CVE-2026-16395 - Integer Overflow

Severity: Critical

CVSS: 9.8

Description: An integer overflow was identified in the Audio/Video component.

Impact: Could lead to memory corruption and potential code execution.

Conditions: No special privileges required.

Notes: Fixed in Firefox 153.

CVE-2026-16406 - Mitigation Bypass

Severity: Critical

CVSS: 9.1

Description: A mitigation bypass was identified in the Networking component.

Impact: Could allow attackers to bypass existing security protections.

Conditions: No special privileges required.

Notes: Fixed in Firefox 153.

CVE-2026-16408 - Integer Overflow

Severity: Critical

CVSS: 9.8

Description: An integer overflow was identified in the Audio/Video: Playback component.

Impact: Could lead to memory corruption and potential code execution.

Conditions: No special privileges required.

Notes: Fixed in Firefox 153.

CVE-2026-16411 - Memory Safety Bugs

Severity: Critical

CVSS: 9.8

Description: Memory safety bugs were present in Firefox 152, with evidence of memory corruption.

Impact: Could be exploited to run arbitrary code.

Conditions: No special privileges required.

Notes: Fixed in Firefox 153.

CVE-2026-16412 - Memory Safety Bugs

Severity: Critical

CVSS: 9.8

Description: Memory safety bugs were present in Firefox ESR 140.12 and Firefox 152, with evidence of memory corruption.

Impact: Could be exploited to run arbitrary code.

Conditions: No special privileges required.

Notes: Fixed in Firefox 153 and Firefox ESR 140.13.


Mitigation

  • Update Firefox to version 153 or later immediately.

  • Update Firefox ESR to version 115.38 or 140.13 or later, depending on your ESR branch.

  • Enable automatic updates where possible to ensure timely patching.

  • Restart the browser after updating to apply the patch.

  • Verify update status across all endpoints using centralised device management tools.


Summary for IT Teams

Products: Mozilla Firefox, Firefox ESR

Threat Level: Critical, CVSS up to 9.8

Action Required: Patch all Firefox and Firefox ESR installations to the fixed versions immediately and confirm deployment across the environment.


Reference


Need Help?

Please get in touch on 1300 769 460 or email us. We are here to help you strengthen your cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.