CVE-2026-16389
9.8Mozilla · Firefox, Thunderbird
An integer overflow vulnerability exists in the NSS Libraries component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.
Executive summary
A critical integer overflow vulnerability in the Mozilla NSS library affects Firefox and Thunderbird, posing a high risk of total system compromise by unauthenticated remote attackers.
Vulnerability
The flaw involves incorrect boundary conditions and an integer overflow within the Network Security Services (NSS) component, which can be triggered by an unauthenticated attacker over the network.
Business impact
The vulnerability carries a CVSS score of 9.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation allows for unauthorized remote code execution, which could lead to complete system takeover, data exfiltration, or the deployment of persistent malware within the corporate network.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately.
Proactive Monitoring: Monitor network traffic for unusual patterns originating from browser-based processes and review system logs for signs of unexpected memory corruption or process crashes.
Compensating Controls: Ensure that endpoint protection software is active and fully updated to detect exploit attempts targeting memory-related vulnerabilities in browser components.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this flaw and the potential for remote code execution, organizations should prioritize the deployment of the version 153 update across all managed endpoints. Failure to remediate this vulnerability leaves systems exposed to severe risk, as the flaw is fully automatable and requires no user interaction to trigger.
More Mozilla CVEs
Sources
Originally found and disclosed by Tomoya Nakanishi, per the CVE Program record.