Description
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the updated CVE description, this vulnerability enables an attacker to bypass security mitigations within the networking component of Mozilla products. The flaw was resolved in Firefox 153 and Thunderbird 153.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird. Versions earlier than 153 of either product are affected. The fix was introduced in release 153 of each product.

Risk and Exploitability

The maintenance team lists a CVSS score of 9.1 and an EPSS probability of less than 1 %. The vulnerability is not yet cataloged in CISA's KEV program. Based on the fact that the flaw resides in the networking layer, the likely attack vector would involve remote delivery of crafted network packets to the vulnerable software, although the official description does not specify this explicitly.

Generated by OpenCVE AI on August 4, 2026 at 05:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 153 or later.
  • Upgrade Mozilla Thunderbird to version 153 or later.
  • Configure network security settings (e.g., enforce strict TLS, disable insecure protocols) to reduce risk while awaiting updates.

Generated by OpenCVE AI on August 4, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153. Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
Title Mitigation bypass in the Networking component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:12.014Z

Reserved: 2026-07-20T21:57:43.911Z

Link: CVE-2026-16406

cve-icon Vulnrichment

Updated: 2026-07-21T19:19:17.006Z

cve-icon NVD

Status : Modified

Published: 2026-07-21T13:17:16.013

Modified: 2026-07-22T20:16:59.507

Link: CVE-2026-16406

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T12:38:18Z

Links: CVE-2026-16406 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure