CVE-2026-16357

9.8

Mozilla · Firefox, Thunderbird

Incorrect boundary conditions in the Graphics component of Mozilla Firefox and Thunderbird allow for potential system compromise.

Executive summary

A critical vulnerability in the Mozilla Graphics component allows unauthenticated attackers to achieve remote code execution, posing a severe risk to system integrity.

Vulnerability

The vulnerability involves incorrect boundary conditions within the Graphics component, which can be exploited by an unauthenticated attacker via the network to achieve memory corruption or potential code execution.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this flaw, as it permits full compromise of the host system without requiring user interaction or authentication. Successful exploitation may lead to total system takeover, unauthorized data exfiltration, and the deployment of persistent malware, resulting in significant operational downtime and potential loss of sensitive corporate data.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the specified fixed versions (153 or the appropriate ESR releases) immediately.

Proactive Monitoring: Monitor network traffic for anomalous patterns originating from browser processes and review system logs for signs of unexpected process termination or execution.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious memory access patterns, as these may mitigate the impact of an exploit attempt while the patch is being deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the potential for remote code execution, this vulnerability represents a high-priority risk to all environments utilizing Mozilla software. IT and security administrators must prioritize the deployment of the provided patches across all workstations and servers to eliminate the exposure window. Ensure that automated update channels are verified for these products to maintain long-term security posture.

More Mozilla CVEs

Sources

Originally found and disclosed by 5up3rh3i, per the CVE Program record.