CVE-2026-16355
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140
CVSS
9.8
Critical
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Jul 21, 2026 · Last modified: Jul 24, 2026 · CWE-843
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2052207
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-68/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-69/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-70/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-71/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-72/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-18458—4.5%
——1Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*.1dCVE-2026-11389—4.5%
——1Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6.1dCVE-2026-61674—49.8%
——15Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or length. An attacker who controls or can impersonate an out_forward Secure Forward destination configured with Shared_Key or Empty_Shared_Key can send an oversized reason during the first handshake and overwrite stack control data. Protected builds reliably terminate, while builds without a stack canary or with a disclosure can allow remote code execution as the Fluent Bit process user. When the opt-in --supervisor mode is used, fork-only respawns preserve the canary and address layout, allowing repeated crash-or-survive probes to support code execution on a hardened build; ordinary exec-based or service-manager restarts do not preserve that state. This issue is fixed in version 5.0.8.2dCVE-2026-940839.4 CRI34.2%
——10Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.1dCVE-2026-933778.8 HIG37.4%
——11Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-917418.8 HIG38.0%
——11Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)7d