Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196739 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-16351PATCHED
mozilla · firefox

Sandbox escape due to use-after-free in the DOM: Navigation component

Description

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Affected Products

VendorProductVersions
mozillafirefox—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mozillafirefoxcert_advisory90%
mozillafirefox esrcert_advisory90%

References

  • https://bugzilla.mozilla.org/show_bug.cgi?id=2045468
  • https://www.mozilla.org/security/advisories/mfsa2026-68/
  • https://www.mozilla.org/security/advisories/mfsa2026-69/
  • https://www.mozilla.org/security/advisories/mfsa2026-70/
  • https://www.mozilla.org/security/advisories/mfsa2026-71/
  • https://www.mozilla.org/security/advisories/mfsa2026-72/

Related News (4 articles)

Tier B
CERT-FR33d ago
Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories33d ago
[NEU] [hoch] Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB34d ago
CVE-2026-16351 | Mozilla Firefox up to 115.37/140.12/152 Navigation use after free
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
115.38140.13153
PublishedJul 21, 2026
Last enriched34d agov2
Trending Score2
Source articles4
Independent3
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-74989EXP
Internally found bugs fixed in Firefox 154
Trending: 34
CRITICALCVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Trending: 32
CRITICALCVE-2026-74961
Side-channel in the Web Audio component
Trending: 32
CRITICALCVE-2026-74940
Use-after-free in the Graphics: Text component
Trending: 32
CRITICALCVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Trending: 32

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions, cweIds
Jul 21, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 34d ago
v2Tier C34d ago

Updated severity to CRITICAL, added affected versions (Firefox up to 115.37/140.12/152), and identified CWE-416 (use-after-free) as the underlying weakness.

affectedVersionscweIds
via VulDB
v134d ago

Initial creation