CVE-2026-16405: Mozilla Firefox
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Affected products
- Mozilla Firefox: before 153.0.0 (fixed in 153.0.0); from 140.1.0, before 140.13.0 (fixed in 140.13.0)
Published 2026-07-21. Last modified 2026-07-22.