Description
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is defined as a mitigation bypass within the DOM‑based networking component of Mozilla Firefox and Mozilla Thunderbird. It is classified as CWE‑693, indicating a failure of a protection mechanism. The official advisory does not articulate a particular defense or data that could be compromised, so the exact consequence of the flaw remains unspecified. Based on the description, it is inferred that the flaw could allow an attacker to bypass network‑level mitigations normally enforced by the browser.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird versions earlier than 153 are affected. The flaw was fixed in Firefox 153 and Thunderbird 153. No older or newer versions are claimed to be vulnerable.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity. The EPSS score is below 1 %, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely observed. The advisory does not provide an explicit attack vector; thus it remains unclear whether remote or local conditions are required. No definitive exploitation path is documented, so impact scope is uncertain.

Generated by OpenCVE AI on August 4, 2026 at 17:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 153 or newer.
  • Upgrade to Mozilla Thunderbird 153 or newer.
  • If an upgrade cannot be performed immediately, discontinue use of the affected browsers until the patch is applied; no public workaround is available.

Generated by OpenCVE AI on August 4, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153. Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
Title Mitigation bypass in the DOM: Networking component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:32.701Z

Reserved: 2026-07-20T21:56:28.223Z

Link: CVE-2026-16370

cve-icon Vulnrichment

Updated: 2026-07-22T16:01:00.654Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:06.860

Modified: 2026-07-24T16:35:27.003

Link: CVE-2026-16370

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:46Z

Links: CVE-2026-16370 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure