Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196739 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-16390PATCHED
mozilla · firefox

Mitigation bypass in the Enterprise Policies component

Description

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Affected Products

VendorProductVersions
mozillafirefox—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mozillafirefoxcert_advisory90%
mozillafirefox esrcert_advisory90%

References

  • https://bugzilla.mozilla.org/show_bug.cgi?id=2044527
  • https://www.mozilla.org/security/advisories/mfsa2026-68/
  • https://www.mozilla.org/security/advisories/mfsa2026-70/
  • https://www.mozilla.org/security/advisories/mfsa2026-71/
  • https://www.mozilla.org/security/advisories/mfsa2026-72/

Related News (4 articles)

Tier B
CERT-FR33d ago
Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories33d ago
[NEU] [hoch] Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB34d ago
CVE-2026-16390 | Mozilla Firefox up to 140.12/152 Enterprise Policies Remote Code Execution
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
140.13153
PublishedJul 21, 2026
Last enriched34d agov2
Tags
remote-code-executionnetwork-accessible
Trending Score2
Source articles4
Independent3
Info Completeness10/14
Missing: epss, kev, exploit, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-74989EXP
Internally found bugs fixed in Firefox 154
Trending: 34
CRITICALCVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Trending: 32
CRITICALCVE-2026-74961
Side-channel in the Web Audio component
Trending: 32
CRITICALCVE-2026-74940
Use-after-free in the Graphics: Text component
Trending: 32
CRITICALCVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: severity, cvssEstimate, affectedVersions, cweIds, mitreAttack, tags
Jul 21, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 34d ago
v2Tier C34d ago

Updated severity from NONE to CRITICAL, added affected versions (Firefox up to 140.12/152), estimated CVSS at 9.0, and added CWE-94 and MITRE T1190 technique tags indicating remote code execution vulnerability.

severitycvssEstimateaffectedVersionscweIdsmitreAttacktags
via VulDB
v134d ago

Initial creation