[NEW] [high] Mozilla Firefox and Firefox ESR: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Mozilla Firefox and Mozilla Firefox ESR to execute arbitrary code, bypass security measures, disclose confidential information, escalate permissions, perform sandbox escapes, manipulate data, trigger a denial-of-service condition, or cause memory corruption.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Mozilla Firefox and Firefox ESR to execute arbitrary code, bypass security measures, disclose confidential information, escalate permissions, perform sandbox escapes, manipulate data, trigger a denial-of-service condition, or cause memory corruption.
- Who is affected
- Users of Mozilla Firefox and Firefox ESR are affected.
- Urgency
- Remediation is high urgency due to the potential for severe exploitation and active attacks.
- Action
- Update to the latest version of Firefox or Firefox ESR to address the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Firefox and Firefox ESR
Get an email when a new Firefox and Firefox ESR advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2458
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-157180.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-157190.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-163490.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-163500.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-163510.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-163520.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-163530.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-163540.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-163550.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-163560.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Mozilla Firefox: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownDSA-6403-1 nss - security updatedebian
- unknownMultiple vulnerabilities in Mozilla Thunderbird (July 23, 2026)cert-fr-avis
- unknownMozilla Products Multiple Vulnerabilitieshkcert
- unknownDSA-6394-1 firefox-esr - security updatedebian
- unknownMultiple vulnerabilities in Mozilla products (July 22, 2026)cert-fr-avis
- criticalCVE-2026-16406: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and…nvd
- highCVE-2026-16405: Information disclosure in the Networking: WebSockets component. This vulnerability was fixed i…nvd
- highCVE-2026-16404: Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.nvd
- mediumCVE-2026-16403: Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and T…nvd
- criticalCVE-2026-16402: Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox …nvd
- highCVE-2026-16401: Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Fi…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31