Threat reportVulnerabilityTL-2026-1878
Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405)
Mozilla Firefox / Thunderbird Information Disclosure (TL-2026-1878) is a high-severity software vulnerability scored CVSS 7.5, first published 2026-08-04. It has no confirmed attribution, affects Mozilla Firefox, references 1 CVE (CVE-2026-16405), maps to 8 MITRE ATT&CK techniques (T1005, T1059, T1071), and is covered by 9 detection rules and 6 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-1878
- Threat ID
- TL-2026-1878
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all-sectors, government administration, finance, health, technology, education, news - media, energy, critical-infrastructure
- Target regions
- Global, North America, Europe, Asia-Pacific, Middle East, 005 - South America, Africa, Oceania
- Detection rules
- 9
- Indicators of compromise
- 6
How Mozilla Firefox / Thunderbird Information Disclosure works
CVE-2026-16405 is a high-severity (CVSS 7.5) information disclosure vulnerability in Mozilla Firefox's and Thunderbird's Networking: WebSockets component. A remote, unauthenticated attacker can leak sensitive data without user interaction by exploiting incorrect handling in the WebSocket protocol stack. The vulnerability is automatable per CISA SSVC assessment, though no exploitation in the wild has been reported as of publication. Fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13, all released July 21, 2026.
CVE-2026-16405 is an information disclosure vulnerability (CWE-200) residing in Mozilla Firefox's Networking: WebSockets component — the implementation of the ws:// and wss:// protocol stacks layered over the HTTP upgrade mechanism. Discovered and reported by security researcher Yaqoub Aldurayhim, the flaw was addressed in the July 21, 2026 release of Firefox 153 (MFSA2026-68) and subsequently expanded to cover Thunderbird (MFSA2026-71, MFSA2026-72) and Firefox ESR (MFSA2026-70).
The vulnerability arises from a defect in the WebSocket networking path's framing, buffer management, or state handling. Unlike standard HTTP requests (which are subject to Same-Origin Policy read restrictions enforced by the browser), WebSockets are designed to provide full-duplex communication channels that cross origins by design — the browser automatically attaches cookies and credentials to the WebSocket handshake. A flaw in how Firefox processes these connections at the networking layer can cause it to leak sensitive information from the browser's process memory, cross-origin response data, or connection state that should remain isolated. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N confirms the vulnerability is network-exploitable, requires no privileges or user interaction (beyond the victim visiting a page), and carries a high confidentiality impact.
CISA's ADP enrichment assigned a CVSS v3.1 base score of 7.5 (High) along with CWE-200 classification, and performed an SSVC assessment rating Exploitation as 'none', Automatable as 'yes', and Technical Impact as 'partial'. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of August 4, 2026, and carries a low EPSS score of 0.256% (17th percentile), indicating a low near-term exploitation probability. However, the automatable rating means that once a working exploit is developed, it could be deployed at scale without manual per-target intervention.
The fix was shipped as part of a significant security release: Firefox 153 also enabled Local Network Access restrictions by default and introduced new extension permission controls for local file access. The underlying Bugzilla report (Bug 2036591) remains restricted from public access, limiting external technical analysis. Mozilla's own advisory rates this vulnerability as 'Low' in their internal severity scale, though the CVSS score from CISA ADP is 7.5 (High). The scope of affected products was expanded within 24 hours of original publication to include Thunderbird across both release and ESR channels.
Organizations running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR should prioritize upgrading to the fixed versions (153 or 140.13+ respectively) as the primary remediation. As a compensating control, network administrators can restrict outbound WebSocket connections (ws://, wss://) to untrusted destinations at the proxy or firewall level, though this may disrupt legitimate real-time web applications.
MITRE ATT&CK techniques used in TL-2026-1878
Collection
T1005 Data from Local System; T1119 Automated Collection
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Affected products and versions in Mozilla Firefox / Thunderbird Information Disclosure
- Mozilla — Firefox
Vulnerable versions: All versions prior to 153.0
Fixed in: 153.0 and later - Mozilla — Firefox ESR
Vulnerable versions: 140.1.0 to 140.12.x
Fixed in: 140.13 and later - Mozilla — Thunderbird
Vulnerable versions: All versions prior to 153.0
Fixed in: 153.0 and later - Mozilla — Thunderbird ESR
Vulnerable versions: 140.x prior to 140.13
Fixed in: 140.13 and later
Remediation for Mozilla Firefox / Thunderbird Information Disclosure
Patches
- Firefox 153 (MFSA2026-68)
- Firefox ESR 140.13 (MFSA2026-70)
- Thunderbird 153 (MFSA2026-71)
- Thunderbird ESR 140.13 (MFSA2026-72)
Immediate actions
- Upgrade Firefox to version 153 or later
- Upgrade Firefox ESR to version 140.13 or later
- Upgrade Thunderbird to version 153 or later
- Upgrade Thunderbird ESR to version 140.13 or later
Workarounds
- Block outbound WebSocket connections (ws://, wss://) to untrusted destinations at proxy/firewall level (may break legitimate applications)
- Enforce application allowlisting to prevent execution of unpatched browser versions
- Restrict Firefox/Thunderbird usage in sensitive environments until patching is verified
- Disable or restrict WebSocket API via enterprise policy (Group Policy / policies.json) for high-security environments
Longer-term hardening
- Establish browser/email-client patch management policy with <72-hour SLA for security updates
- Deploy centralized browser management (Group Policy / MDM) for version tracking and enforcement
- Subscribe to Mozilla Security Advisories feed for proactive vulnerability alerting
- Implement browser isolation or sandboxing for high-value user segments
CVEs associated with Mozilla Firefox / Thunderbird Information Disclosure
Weaknesses (CWE) in Mozilla Firefox / Thunderbird Information Disclosure
Timeline of Mozilla Firefox / Thunderbird Information Disclosure
- Yaqoub Aldurayhim credited as the discoverer in the Mozilla advisory. The Bugzilla report (Bug 2036591) is access-restricted.
- CISA-ADP performs enrichment, assigning CVSS v3.1 base score 7.5 (HIGH) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, CWE-200 classification, and SSVC assessment (Exploitation: none, Automatable: yes, Technical Impact: partial).
- Mozilla releases Firefox 153 and Firefox ESR 140.13 containing the fix for CVE-2026-16405. The release also enables Local Network Access restrictions by default and introduces new extension local-file permissions.
- CVE-2026-16405 is published by Mozilla as part of MFSA2026-68 for Firefox 153, reporting an information disclosure vulnerability in the Networking: WebSockets component discovered by Yaqoub Aldurayhim.
- NIST completes initial analysis adding affected CPE configurations: Firefox versions up to (excluding) 153.0.0, and Firefox ESR versions from (including) 140.1.0 up to (excluding) 140.13.0.
- Mozilla expands the scope of CVE-2026-16405 to include Thunderbird 153 (MFSA2026-71) and Thunderbird ESR 140.13 (MFSA2026-72), and NIST completes initial CPE configuration analysis for the vulnerability.
- CVE-2026-16405 remains absent from the CISA Known Exploited Vulnerabilities catalog as of the August 4, 2026 catalog update (1,660 total entries). No exploitation in the wild has been reported.
- HKCERT publishes a security bulletin warning of the Mozilla Firefox information disclosure vulnerability, citing the underlying Mozilla advisory and recommending immediate patching.
Sources cited for Mozilla Firefox / Thunderbird Information Disclosure
- Mozilla Foundation Security Advisory 2026-68 (Firefox 153)
- Mozilla Foundation Security Advisory 2026-70 (Firefox ESR 140.13)
- Mozilla Foundation Security Advisory 2026-71 (Thunderbird 153)
- Mozilla Foundation Security Advisory 2026-72 (Thunderbird ESR 140.13)
- NVD — CVE-2026-16405
- Bugzilla Bug 2036591
- GitHub Advisory GHSA-cjjv-h8qx-pq7p
- Firefox 153 Release Notes
- Firefox 153 Developer Release Notes (MDN)
- HKCERT Security Bulletin — Mozilla Firefox Information Disclosure Vulnerability
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-1878
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1878 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.