2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16406 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16405 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR... |
| CVE-2026-16404 | HIGH | 7.4 | 0.2% | Jul 21, 2026 | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16403 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16402 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16401 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird ... |
| CVE-2026-16400 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16399 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16398 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16397 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16396 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,... |
| CVE-2026-16395 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16394 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16393 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunder... |
| CVE-2026-16392 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ... |
| CVE-2026-16391 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140... |
| CVE-2026-16390 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,... |
| CVE-2026-16389 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firef... |
| CVE-2026-16388 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16387 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thund... |
| CVE-2026-16386 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi... |
| CVE-2026-16385 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi... |
| CVE-2026-16384 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi... |
| CVE-2026-16383 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thu... |
| CVE-2026-16382 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now