VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 207 of 1202 · EPSS data 2026.08.08
ReviewCritical
CVE-2026-16368

Mozilla Firefox, Thunderbird, firefox

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16363

Mozilla Firefox, Thunderbird, firefox

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16362

Mozilla Firefox, Thunderbird, firefox

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16361

Mozilla Firefox, Thunderbird, firefox

Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16360

Mozilla Firefox, Thunderbird, firefox

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16359

Mozilla Firefox, Thunderbird, firefox

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16358

Mozilla Firefox, Thunderbird, firefox

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16357

Mozilla Firefox, Thunderbird, firefox

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16356

Mozilla Firefox, Thunderbird, firefox

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16355

Mozilla Firefox, Thunderbird, firefox

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16354

Mozilla Firefox, Thunderbird, firefox

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

The CVSS severity warrants an early asset and exposure review.