CVE-2026-16375
9.8Mozilla · Firefox, Thunderbird
A site isolation vulnerability in the Networking: HTTP component of Mozilla Firefox and Thunderbird allows for potential cross-origin data exposure or system compromise.
Executive summary
A critical vulnerability in the Mozilla networking stack allows unauthenticated remote attackers to bypass site isolation, creating a high risk of total system compromise.
Vulnerability
This is a site isolation flaw within the Networking: HTTP component. The vulnerability is exploitable by an unauthenticated remote attacker via the network, requiring no user interaction.
Business impact
The CVSS score of 9.8 reflects the severity of this issue, as it allows for full confidentiality, integrity, and availability impact. A successful exploit could lead to complete system compromise, unauthorized access to sensitive user data, and significant reputational damage for organizations relying on these browsers for secure communication.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 153 or later, or to ESR version 140.13 or later, to apply the necessary security patches.
Proactive Monitoring: Monitor network traffic logs for unusual HTTP requests or unexpected browser behavior that may indicate exploitation attempts.
Compensating Controls: Ensure that browser-based security policies are strictly enforced and consider using endpoint protection software to monitor for unauthorized process execution.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this vulnerability and the potential for remote exploitation, immediate patching is required across all organizational endpoints. IT administrators should prioritize the deployment of Firefox and Thunderbird updates to ensure that all instances are on a secure version, thereby neutralizing the risk of this site isolation bypass.
More Mozilla CVEs
Sources
Originally found and disclosed by pakhunov.anton.n, per the CVE Program record.