Kaspersky ID:
KLA91170
Дата обнаружения:
21/07/2026
Обновлено:
23/07/2026

Описание

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in MIME header parser for forwarding can be exploited remotely to cause denial of service.
  2. Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
  3. Denial of service vulnerability in the Audio/Video: cubeb component can be exploited remotely to cause denial of service.
  4. A remote code execution vulnerability in the WebRTC: Audio/Video component can be exploited remotely to execute arbitrary code.
  5. A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
  6. A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
  7. Security vulnerability can be exploited to bypass security restrictions.
  8. Denial of service vulnerability in the Audio/Video: Playback component can be exploited remotely to cause denial of service.
  9. Security vulnerability in the DOM: Workers component can be exploited to bypass security restrictions.
  10. Denial of service vulnerability in the DOM: Bindings (WebIDL) component can be exploited remotely to cause denial of service.
  11. Information disclosure vulnerability in the Graphics: ImageLib component can be exploited to obtain sensitive information.
  12. Denial of service vulnerability in the Disability Access APIs component can be exploited remotely to cause denial of service.
  13. Denial of service vulnerability in the JavaScript: WebAssembly component can be exploited remotely to cause denial of service.
  14. A remote code execution vulnerability in the JavaScript: WebAssembly component can be exploited remotely to execute arbitrary code.
  15. Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
  16. Security vulnerability in the DOM: Networking component can be exploited to bypass security restrictions.
  17. Security vulnerability in the DOM: Content Processes component can be exploited to bypass security restrictions.
  18. Information disclosure vulnerability in the Framework component in DevTools can be exploited to obtain sensitive information.
  19. Denial of service vulnerability in the Graphics: WebGPU component can be exploited remotely to cause denial of service.
  20. Security vulnerability in the PDF Viewer component can be exploited to bypass security restrictions.
  21. Denial of service vulnerability in the DOM: Copy & Paste and Drag & Drop component can be exploited remotely to cause denial of service.
  22. Security vulnerability in the Networking component can be exploited to bypass security restrictions.
  23. Security vulnerability in the Networking: DNS component can be exploited to bypass security restrictions.
  24. Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
  25. Information disclosure vulnerability in the Graphics: WebGPU component can be exploited to obtain sensitive information.
  26. A remote code execution vulnerability in the Libraries component in NSS can be exploited remotely to execute arbitrary code.
  27. Security vulnerability in the Enterprise Policies component can be exploited to bypass security restrictions.
  28. Information disclosure vulnerability in the Storage: IndexedDB component can be exploited to obtain sensitive information.
  29. Denial of service vulnerability in the Audio/Video: GMP component can be exploited remotely to cause denial of service.
  30. Security vulnerability in the DOM: Security component can be exploited to bypass security restrictions.
  31. A remote code execution vulnerability in the Audio/Video component can be exploited remotely to execute arbitrary code.
  32. Security vulnerability in WebExtensions can be exploited to bypass security restrictions.
  33. Information disclosure vulnerability in the DOM: Security component can be exploited to obtain sensitive information.
  34. Security vulnerability in the Data Loss Prevention component can be exploited to bypass security restrictions.
  35. A remote code execution vulnerability in the Graphics: ImageLib component can be exploited remotely to execute arbitrary code.
  36. Security UI vulnerability in the Address Bar component can be exploited to spoof user interface.
  37. Information disclosure vulnerability in the Networking: WebSockets component can be exploited to obtain sensitive information.
  38. A remote code execution vulnerability in the Audio/Video: Playback component can be exploited remotely to execute arbitrary code.
  39. Denial of service vulnerability in the Security: PSM component can be exploited remotely to cause denial of service.
  40. A remote code execution vulnerability in Firefox 153 can be exploited remotely to execute arbitrary code.
  41. A remote code execution vulnerability in Firefox ESR 140 can be exploited remotely to execute arbitrary code.
  42. A remote code execution vulnerability in Firefox ESR 115 can be exploited remotely to execute arbitrary code.

Первичный источник обнаружения

Список CVE

  • CVE-2026-16349
    critical
  • CVE-2026-16350
    critical
  • CVE-2026-16351
    critical
  • CVE-2026-16352
    critical
  • CVE-2026-16353
    critical
  • CVE-2026-16354
    critical
  • CVE-2026-16355
    critical
  • CVE-2026-16356
    critical
  • CVE-2026-16357
    critical
  • CVE-2026-16358
    critical
  • CVE-2026-16359
    critical
  • CVE-2026-16360
    critical
  • CVE-2026-16362
    critical
  • CVE-2026-16363
    critical
  • CVE-2026-16364
    critical
  • CVE-2026-16365
    critical
  • CVE-2026-16366
    critical
  • CVE-2026-16367
    critical
  • CVE-2026-16368
    critical
  • CVE-2026-16369
    critical
  • CVE-2026-16370
    critical
  • CVE-2026-16371
    critical
  • CVE-2026-16372
    critical
  • CVE-2026-16374
    critical
  • CVE-2026-16375
    critical
  • CVE-2026-16376
    critical
  • CVE-2026-16377
    critical
  • CVE-2026-16378
    critical
  • CVE-2026-16379
    critical
  • CVE-2026-16380
    critical
  • CVE-2026-16381
    critical
  • CVE-2026-16382
    critical
  • CVE-2026-16383
    critical
  • CVE-2026-16384
    critical
  • CVE-2026-16385
    critical
  • CVE-2026-16386
    critical
  • CVE-2026-16387
    critical
  • CVE-2026-16388
    critical
  • CVE-2026-16389
    critical
  • CVE-2026-16390
    critical
  • CVE-2026-16391
    critical
  • CVE-2026-16392
    unknown
  • CVE-2026-16393
    critical
  • CVE-2026-16394
    critical
  • CVE-2026-16395
    critical
  • CVE-2026-16396
    critical
  • CVE-2026-16398
    critical
  • CVE-2026-16399
    critical
  • CVE-2026-16400
    critical
  • CVE-2026-16401
    critical
  • CVE-2026-16402
    critical
  • CVE-2026-16403
    high
  • CVE-2026-16405
    critical
  • CVE-2026-16406
    critical
  • CVE-2026-16407
    critical
  • CVE-2026-16408
    critical
  • CVE-2026-16409
    critical
  • CVE-2026-16410
    critical
  • CVE-2026-16411
    critical
  • CVE-2026-16412
    critical
  • CVE-2026-14899
    unknown

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Do you want to save your changes?
Your message has been sent successfully.