2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16406CRITICAL9.1Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16405HIGH7.5Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR...
CVE-2026-16404HIGH7.4Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16403MEDIUM6.5Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16402CRITICAL9.8Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16401HIGH8.8Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird ...
CVE-2026-16400HIGH7.5Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16399HIGH7.5Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16398HIGH7.5Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16397MEDIUM6.5Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16396HIGH8.8Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,...
CVE-2026-16395CRITICAL9.8Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16394CRITICAL9.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16393CRITICAL9.1Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunder...
CVE-2026-16392CRITICAL9.1JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird ...
CVE-2026-16391HIGH7.5Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140...
CVE-2026-16390CRITICAL9.1Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,...
CVE-2026-16389CRITICAL9.8Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firef...
CVE-2026-16388CRITICAL9.8Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16387CRITICAL9.8Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thund...
CVE-2026-16386HIGH7.5Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi...
CVE-2026-16385HIGH7.5Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi...
CVE-2026-16384HIGH7.5Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi...
CVE-2026-16383CRITICAL9.8Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thu...
CVE-2026-16382CRITICAL9.8Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now