DIRAS TAKE
Urgent: this is a remotely exploitable sandbox escape requiring no authentication or user interaction, making it high priority to isolate exposed Firefox installs and prepare to apply vendor updates as soon as they are published.
What is CVE-2026-16367?
Remote attackers can escape the Firefox sandbox and execute arbitrary code against Firefox (CVE-2026-16367); the flaw is a memory safety issue (CWE-119) in the Disability Access APIs component. The vulnerability carries a CVSS 3.1 score of 10.0 and, according to the published vector, requires only network access with no privileges and no user interaction. Reporting indicates the issue was addressed in Firefox 153 and Thunderbird 153, implying earlier releases are affected.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-16367 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-16367
- Follow Mozilla guidance and apply their security update as soon as it is published.
- Restrict network exposure of systems running Firefox and block untrusted sites where possible.
- Monitor browser crash logs and endpoint telemetry for signs of memory corruption or sandbox escapes.
- Temporarily enforce additional browser hardening and content filtering until a patch is applied.
Frequently asked questions
Is CVE-2026-16367 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-16367?
Third-party reporting states the issue was fixed in Firefox 153 (and in Thunderbird 153), which implies earlier Firefox releases are affected.
Is there a patch for CVE-2026-16367?
No patch was available as of 2026-09-29; monitor Mozilla advisories and apply their update when published.
Does CVE-2026-16367 require authentication?
No; the published CVSS vector shows no privileges and no user interaction are required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-16367
- cve.org/CVERecord?id=CVE-2026-16367
- bugzilla.mozilla.org/show_bug.cgi?id=2050627
- mozilla.org/security/advisories/mfsa2026-68
- mozilla.org/security/advisories/mfsa2026-71
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026