
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16390 is a mitigation bypass vulnerability in the Enterprise Policies component of Mozilla Firefox and Thunderbird, classified as a Protection Mechanism Failure (CWE-693). Discovered by researcher Souma Ohsawa and disclosed on July 21, 2026, it affects Firefox versions prior to 153, Firefox ESR versions prior to 140.13, Thunderbird versions prior to 153, and Thunderbird ESR versions prior to 140.13. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per NVD scoring, though Mozilla rates its impact as moderate in its advisories (Mozilla Advisory Firefox 153, Mozilla Advisory ESR 140.13).
The vulnerability is rooted in a Protection Mechanism Failure (CWE-693) within Firefox's Enterprise Policies component, which organizations use to enforce browser security controls across managed deployments. An attacker can exploit this flaw over the network without authentication or user interaction to circumvent security policies enforced through the Enterprise Policies mechanism, potentially accessing restricted functionality or content that policies were intended to block. The bug is tracked internally as Mozilla Bug 2044527, reported by Souma Ohsawa, though the bug report is access-restricted (Mozilla Advisory Firefox 153, Mozilla Advisory ESR 140.13). No public proof-of-concept code has been identified.
Successful exploitation allows an unauthenticated network attacker to bypass Enterprise Policies security controls without any user interaction, resulting in high confidentiality and integrity impact. Attackers can read sensitive data and modify browser settings or content that organizational policies were designed to restrict, potentially undermining security baselines across entire managed Firefox or Thunderbird deployments. Availability is not directly impacted, but the policy bypass could enable further attacks within enterprise environments by circumventing controls such as site blocking, extension restrictions, or privacy settings (Mozilla Advisory ESR 140.13, GitHub Advisory).
As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-16390. The EPSS score is approximately 0.00159 (low probability of exploitation in the near term), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies the vulnerability as automatable with total technical impact, but with no known exploitation at this time (Mozilla Advisory ESR 140.13, GitHub Advisory).
Mozilla has released patches addressing CVE-2026-16390 in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13. Organizations relying on Enterprise Policies for security controls should prioritize upgrading to these versions immediately, as the bypass could undermine policy-enforced security baselines across managed deployments. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Mozilla Advisory Firefox 153, Mozilla Advisory ESR 140.13).
Mozilla rated the vulnerability as moderate impact in its official advisories, while NVD assigned a higher CVSS score of 9.1 (Critical), reflecting a discrepancy in severity assessment between the vendor and the national database. Downstream Linux distributions including SUSE, openSUSE, Red Hat, AlmaLinux, Rocky Linux, and Slackware have issued their own security updates incorporating the fix. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability tracking and patch notification channels (Mozilla Advisory ESR 140.13, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."