← Back to browse · API

CVE-2026-16367

Severity
CRITICAL
CVSS
10.0
EPSS
0.00375
Risk score
40.13
CISA KEV
No
PoC
Yes
Published
2026-07-21
Modified
2026-07-22
First seen
2026-08-05
Aliases
EUVD-2026-46200, GHSA-856J-8V8V-WVFQ
Products
linux, mozilla:firefox, mozilla:thunderbird, suse
Sources
nvd CVE-2026-16367
euvd EUVD-2026-46200
packetstorm 8210fed256f9480c5e59b702|CVE-2026-16367

Description

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

References