Description
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to bypass built‑in network security mitigations in Mozilla's Networking component. By exploiting this flaw, malicious traffic could be routed through the application without triggering standard defenses, effectively granting the attacker the ability to conduct unauthorized network operations. This weakness is identified as CWE‑693, indicating improper control of a resource that requires authorization. An attacker could therefore compromise confidentiality or integrity of network communications or use the affected applications as a conduit for malicious payloads.

Affected Systems

Mozilla Firefox versions earlier than 153 and Thunderbird before 153 are affected. The flaw has been addressed in Firefox 153 and Thunderbird 153, so any installation of these products without the confirmed patch is at risk.

Risk and Exploitability

The CVSS score of 9.1 marks this as a critical vulnerability, while the EPSS score of less than 1% suggests that active exploitation in the wild is currently low but not impossible. The vulnerability is not listed in the CISA KEV catalog, meaning no known mass exploitation campaigns have leveraged it yet. Given the network‑based nature inferred from the description, attackers would likely need access to traffic passing through the affected applications, making the attack vector network‑remote. The combination of high severity and low current exploitation probability creates a pressure to patch promptly while remaining vigilant for suspicious network patterns.

Generated by OpenCVE AI on August 4, 2026 at 05:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 153 or later, and update Thunderbird to 153 or later, downloading the latest release from Mozilla's official site.
  • Ensure the operating system and all underlying libraries—including networking stacks and cryptographic modules—are updated to their latest security releases, guaranteeing that related mitigations remain intact.
  • Configure the host firewall or network security appliance to log and alert on anomalous connection attempts originating from Firefox or Thunderbird, helping detect any residual bypass attempts.

Generated by OpenCVE AI on August 4, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153. Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
Title Mitigation bypass in the Networking component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:43.465Z

Reserved: 2026-07-20T21:56:49.052Z

Link: CVE-2026-16380

cve-icon Vulnrichment

Updated: 2026-07-22T17:10:18.245Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:13.163

Modified: 2026-07-24T16:39:45.420

Link: CVE-2026-16380

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:55Z

Links: CVE-2026-16380 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure