2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16381 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140... |
| CVE-2026-16380 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16379 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 1... |
| CVE-2026-16378 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderb... |
| CVE-2026-16377 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderb... |
| CVE-2026-16376 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16375 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,... |
| CVE-2026-16374 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR ... |
| CVE-2026-16373 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16372 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbir... |
| CVE-2026-16371 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, ... |
| CVE-2026-16370 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16369 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.... |
| CVE-2026-16368 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Fir... |
| CVE-2026-16367 | CRITICAL | 10 | 0.4% | Jul 21, 2026 | Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 1... |
| CVE-2026-16366 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16365 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefo... |
| CVE-2026-16364 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Th... |
| CVE-2026-16363 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 14... |
| CVE-2026-16362 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Th... |
| CVE-2026-16361 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we pre... |
| CVE-2026-16360 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence... |
| CVE-2026-16359 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ES... |
| CVE-2026-16358 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.... |
| CVE-2026-16357 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now