Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405) — Threadlinqs Intelligence
As of 2026-08-04, Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 6 indicators of compromise.
Threat ID: TL-2026-1878 · Severity: HIGH · CVSS: 7.5 · Status: ACTIVE · Category: VULNERABILITY
CVE-2026-16405 is a high-severity (CVSS 7.5) information disclosure vulnerability in Mozilla Firefox's and Thunderbird's Networking: WebSockets component. A remote, unauthenticated attacker can leak
CVE-2026-16405 is an information disclosure vulnerability (CWE-200) residing in Mozilla Firefox's Networking: WebSockets component — the implementation of the ws:// and wss:// protocol stacks layered over the HTTP upgrade mechanism. Discovered and reported by security researcher Yaqoub Aldurayhim, the flaw was addressed in the July 21, 2026 release of Firefox 153 (MFSA2026-68) and subsequently expanded to cover Thunderbird (MFSA2026-71, MFSA2026-72) and Firefox ESR (MFSA2026-70).
The vulnerability arises from a defect in the WebSocket networking path's framing, buffer management, or state handling. Unlike standard HTTP requests (which are subject to Same-Origin Policy read restrictions enforced by the browser), WebSockets are designed to provide full-duplex communication channels that cross origins by design — the browser automatically attaches cookies and credentials to the WebSocket handshake. A flaw in how Firefox processes these connections at the networking layer can cause it to leak sensitive information from the browser's process memory, cross-origin response data, or connection state that should remain isolated. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N confirms the vulnerability is network-exploitable, requires no privileges or user interaction (beyond the victim visiting a page), and carries a high confidentiality impact.
CISA's ADP enrichment assigned a CVSS v3.1 base score of 7.5 (High) along with CWE-200 classification, and performed an SSVC assessment rating Exploitation as 'none', Automatable as 'yes', and Technical Impact as 'partial'. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of August 4, 2026, and carries a low EPSS score of 0.256% (17th percentile), indicating a low near-term exploitation probability. However, the automatable rating means that once a working exploit is developed, it could be deployed at scale without manual per-target intervention.
The fix was shipped as part of a significant security release: Firefox 153 also enabled Local Network Access restrictions by default and introduced new extension permission controls for local file access. The underlying Bugzilla report (Bug 2036591) remains restricted from public access, limiting external technical analysis. Mozilla's own advisory rates this vulnerability as 'Low' in their internal severity scale, though the CVSS score from CISA ADP is 7.5 (High). The scope of affected products was expanded within 24 hours of original publication to include Thunderbird across both release and ESR channels.
Organizations running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR should prioritize upgrading to the fixed versions (153 or 140.13+ respectively) as the primary remediation. As a compensating control, network administrators can restrict outbound WebSocket connections (ws://, wss://) to untrusted destinations at the proxy or firewall level, though this may disrupt legitimate real-time web applications.
Target sectors: all-sectors, government administration, finance, health, technology, education, news - media, energy, critical-infrastructure
Target regions: Global, North America, Europe, Asia-Pacific, Middle East, 005 - South America, Africa, Oceania
Detections & IOCs
As of 2026-08-09, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 6 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-16405, T1190, T1566, T1059, T1539, T1528, T1005, T1119, T1071