Threat reportVulnerabilityTL-2026-1878

Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405)

highACTIVE

Mozilla Firefox / Thunderbird Information Disclosure (TL-2026-1878) is a high-severity software vulnerability scored CVSS 7.5, first published 2026-08-04. It has no confirmed attribution, affects Mozilla Firefox, references 1 CVE (CVE-2026-16405), maps to 8 MITRE ATT&CK techniques (T1005, T1059, T1071), and is covered by 9 detection rules and 6 indicators of compromise.

CVSS
7.5/10High
CVEs
1Referenced vulnerabilities
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-1878

Threat ID
TL-2026-1878
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all-sectors, government administration, finance, health, technology, education, news - media, energy, critical-infrastructure
Target regions
Global, North America, Europe, Asia-Pacific, Middle East, 005 - South America, Africa, Oceania
Detection rules
9
Indicators of compromise
6

How Mozilla Firefox / Thunderbird Information Disclosure works

CVE-2026-16405 is a high-severity (CVSS 7.5) information disclosure vulnerability in Mozilla Firefox's and Thunderbird's Networking: WebSockets component. A remote, unauthenticated attacker can leak sensitive data without user interaction by exploiting incorrect handling in the WebSocket protocol stack. The vulnerability is automatable per CISA SSVC assessment, though no exploitation in the wild has been reported as of publication. Fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13, all released July 21, 2026.

CVE-2026-16405 is an information disclosure vulnerability (CWE-200) residing in Mozilla Firefox's Networking: WebSockets component — the implementation of the ws:// and wss:// protocol stacks layered over the HTTP upgrade mechanism. Discovered and reported by security researcher Yaqoub Aldurayhim, the flaw was addressed in the July 21, 2026 release of Firefox 153 (MFSA2026-68) and subsequently expanded to cover Thunderbird (MFSA2026-71, MFSA2026-72) and Firefox ESR (MFSA2026-70).

The vulnerability arises from a defect in the WebSocket networking path's framing, buffer management, or state handling. Unlike standard HTTP requests (which are subject to Same-Origin Policy read restrictions enforced by the browser), WebSockets are designed to provide full-duplex communication channels that cross origins by design — the browser automatically attaches cookies and credentials to the WebSocket handshake. A flaw in how Firefox processes these connections at the networking layer can cause it to leak sensitive information from the browser's process memory, cross-origin response data, or connection state that should remain isolated. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N confirms the vulnerability is network-exploitable, requires no privileges or user interaction (beyond the victim visiting a page), and carries a high confidentiality impact.

CISA's ADP enrichment assigned a CVSS v3.1 base score of 7.5 (High) along with CWE-200 classification, and performed an SSVC assessment rating Exploitation as 'none', Automatable as 'yes', and Technical Impact as 'partial'. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of August 4, 2026, and carries a low EPSS score of 0.256% (17th percentile), indicating a low near-term exploitation probability. However, the automatable rating means that once a working exploit is developed, it could be deployed at scale without manual per-target intervention.

The fix was shipped as part of a significant security release: Firefox 153 also enabled Local Network Access restrictions by default and introduced new extension permission controls for local file access. The underlying Bugzilla report (Bug 2036591) remains restricted from public access, limiting external technical analysis. Mozilla's own advisory rates this vulnerability as 'Low' in their internal severity scale, though the CVSS score from CISA ADP is 7.5 (High). The scope of affected products was expanded within 24 hours of original publication to include Thunderbird across both release and ESR channels.

Organizations running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR should prioritize upgrading to the fixed versions (153 or 140.13+ respectively) as the primary remediation. As a compensating control, network administrators can restrict outbound WebSocket connections (ws://, wss://) to untrusted destinations at the proxy or firewall level, though this may disrupt legitimate real-time web applications.

MITRE ATT&CK techniques used in TL-2026-1878

Collection

T1005 Data from Local System; T1119 Automated Collection

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Affected products and versions in Mozilla Firefox / Thunderbird Information Disclosure

  • Mozilla — Firefox
    Vulnerable versions: All versions prior to 153.0
    Fixed in: 153.0 and later
  • Mozilla — Firefox ESR
    Vulnerable versions: 140.1.0 to 140.12.x
    Fixed in: 140.13 and later
  • Mozilla — Thunderbird
    Vulnerable versions: All versions prior to 153.0
    Fixed in: 153.0 and later
  • Mozilla — Thunderbird ESR
    Vulnerable versions: 140.x prior to 140.13
    Fixed in: 140.13 and later

Remediation for Mozilla Firefox / Thunderbird Information Disclosure

Patches

  • Firefox 153 (MFSA2026-68)
  • Firefox ESR 140.13 (MFSA2026-70)
  • Thunderbird 153 (MFSA2026-71)
  • Thunderbird ESR 140.13 (MFSA2026-72)

Immediate actions

  • Upgrade Firefox to version 153 or later
  • Upgrade Firefox ESR to version 140.13 or later
  • Upgrade Thunderbird to version 153 or later
  • Upgrade Thunderbird ESR to version 140.13 or later

Workarounds

  • Block outbound WebSocket connections (ws://, wss://) to untrusted destinations at proxy/firewall level (may break legitimate applications)
  • Enforce application allowlisting to prevent execution of unpatched browser versions
  • Restrict Firefox/Thunderbird usage in sensitive environments until patching is verified
  • Disable or restrict WebSocket API via enterprise policy (Group Policy / policies.json) for high-security environments

Longer-term hardening

  • Establish browser/email-client patch management policy with <72-hour SLA for security updates
  • Deploy centralized browser management (Group Policy / MDM) for version tracking and enforcement
  • Subscribe to Mozilla Security Advisories feed for proactive vulnerability alerting
  • Implement browser isolation or sandboxing for high-value user segments

CVEs associated with Mozilla Firefox / Thunderbird Information Disclosure

CVE-2026-16405

Weaknesses (CWE) in Mozilla Firefox / Thunderbird Information Disclosure

CWE-200

Timeline of Mozilla Firefox / Thunderbird Information Disclosure

  • Yaqoub Aldurayhim credited as the discoverer in the Mozilla advisory. The Bugzilla report (Bug 2036591) is access-restricted.
  • CISA-ADP performs enrichment, assigning CVSS v3.1 base score 7.5 (HIGH) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, CWE-200 classification, and SSVC assessment (Exploitation: none, Automatable: yes, Technical Impact: partial).
  • Mozilla releases Firefox 153 and Firefox ESR 140.13 containing the fix for CVE-2026-16405. The release also enables Local Network Access restrictions by default and introduces new extension local-file permissions.
  • CVE-2026-16405 is published by Mozilla as part of MFSA2026-68 for Firefox 153, reporting an information disclosure vulnerability in the Networking: WebSockets component discovered by Yaqoub Aldurayhim.
  • NIST completes initial analysis adding affected CPE configurations: Firefox versions up to (excluding) 153.0.0, and Firefox ESR versions from (including) 140.1.0 up to (excluding) 140.13.0.
  • Mozilla expands the scope of CVE-2026-16405 to include Thunderbird 153 (MFSA2026-71) and Thunderbird ESR 140.13 (MFSA2026-72), and NIST completes initial CPE configuration analysis for the vulnerability.
  • CVE-2026-16405 remains absent from the CISA Known Exploited Vulnerabilities catalog as of the August 4, 2026 catalog update (1,660 total entries). No exploitation in the wild has been reported.
  • HKCERT publishes a security bulletin warning of the Mozilla Firefox information disclosure vulnerability, citing the underlying Mozilla advisory and recommending immediate patching.

Sources cited for Mozilla Firefox / Thunderbird Information Disclosure

Detection coverage for TL-2026-1878

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1878 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats