CVE-2026-106016: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.

Affected products

  • Mozilla Firefox: before 157.0.1 (fixed in 157.0.1)

Published 2026-10-06. Last modified 2026-10-08.