CVE-2026-12295
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunde
CVSS
9.6
Critical
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Published: Jun 16, 2026 · Last modified: Jul 15, 2026 · CWE-693 · CWE-653
0.4%EPSS · 30 days0.4%
2026-06-302026-07-21
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2040160
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-57/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-58/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-59/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-60/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-61/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27717
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27733
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27734
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:29940
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30846
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33445
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36100
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36101
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36102
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36103
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:37210
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:37391
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:38506
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:38750
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-63071—6.5%
——2Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.22hCVE-2026-53421—20.9%
——6Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.22hCVE-2026-53405—7.1%
——2Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.22hCVE-2026-449827.2 HIG12.2%
——4CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRequestFromRequest allocated a request body buffer from max(r.ContentLength, 0), so HTTP/1.1 requests using Transfer-Encoding: chunked and HTTP/2 requests without a content-length header produced an empty body and caused WAF rules targeting REQUEST_BODY, BODY_ARGS, ARGS_POST, JSON, or XML to be skipped. This issue is fixed in version 1.7.8.4dCVE-2026-560876.1 MED4.1%
——1Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data.6dCVE-2026-499818.2 HIG28.5%
——9Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0.5d