2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16388 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16387 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thund... |
| CVE-2026-16383 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thu... |
| CVE-2026-16382 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153... |
| CVE-2026-16381 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140... |
| CVE-2026-16380 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16377 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderb... |
| CVE-2026-16375 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,... |
| CVE-2026-16370 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16369 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.... |
| CVE-2026-16368 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Fir... |
| CVE-2026-16367 | CRITICAL | 10 | 0.4% | Jul 21, 2026 | Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 1... |
| CVE-2026-16364 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Th... |
| CVE-2026-16363 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 14... |
| CVE-2026-16361 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we pre... |
| CVE-2026-16360 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence... |
| CVE-2026-16359 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ES... |
| CVE-2026-16358 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.... |
| CVE-2026-16357 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38... |
| CVE-2026-16356 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-16355 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115... |
| CVE-2026-16353 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38... |
| CVE-2026-16352 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-16351 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Fire... |
| CVE-2026-16350 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now