CVE-2026-16389

9.8

Mozilla · Firefox, Thunderbird

An integer overflow vulnerability exists in the NSS Libraries component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.

Executive summary

A critical integer overflow vulnerability in the Mozilla NSS library affects Firefox and Thunderbird, posing a high risk of total system compromise by unauthenticated remote attackers.

Vulnerability

The flaw involves incorrect boundary conditions and an integer overflow within the Network Security Services (NSS) component, which can be triggered by an unauthenticated attacker over the network.

Business impact

The vulnerability carries a CVSS score of 9.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation allows for unauthorized remote code execution, which could lead to complete system takeover, data exfiltration, or the deployment of persistent malware within the corporate network.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately.

Proactive Monitoring: Monitor network traffic for unusual patterns originating from browser-based processes and review system logs for signs of unexpected memory corruption or process crashes.

Compensating Controls: Ensure that endpoint protection software is active and fully updated to detect exploit attempts targeting memory-related vulnerabilities in browser components.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this flaw and the potential for remote code execution, organizations should prioritize the deployment of the version 153 update across all managed endpoints. Failure to remediate this vulnerability leaves systems exposed to severe risk, as the flaw is fully automatable and requires no user interaction to trigger.

More Mozilla CVEs

Sources

Originally found and disclosed by Tomoya Nakanishi, per the CVE Program record.