CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16389

criticalCVSS 9.8covered by 6 sourcesfirst seen 2026-07-21
Tomoya Nakanishi discovered a flaw in nss, the Mozilla Network Security Service library, which may result in execution of arbitrary code if a specially crafted certificate is processed. https://security-tracker.debian.org/tracker/DSA-6403-1

CSIRTS triage

What
A flaw in nss may allow execution of arbitrary code if a specially crafted certificate is processed.
Who is affected
Users of the nss library are affected.
Urgency
Remediation is urgent due to the potential for arbitrary code execution.
Action
Update nss to the latest version to mitigate the vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-16389

Get an email if CVE-2026-16389 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (6)

External references

NVD record for CVE-2026-16389

CVE.org record

Embed the live status

CVE-2026-16389 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16389 status](https://www.csirts.com/badge/CVE-2026-16389)](https://www.csirts.com/cve/CVE-2026-16389)