CVE-2026-16361
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enoug
CVSS
9.8
Critical
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Published: Jul 21, 2026 · Last modified: Jul 24, 2026 · CWE-119
0.3%EPSS · 30 days0.3%
2026-08-142026-09-11
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-879337.3 HIG23.2%
——7A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.2dCVE-2026-879319.6 CRI37.7%
——11A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-874898.8 HIG14.1%
——4Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)2dCVE-2026-874448.8 HIG37.3%
——11Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-867167.3 HIG27.7%
——8A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.4dCVE-2026-796028.8 HIG3.0%
——1A guest with a PCI device assigned that has at least a BAR on the IO port
space can trigger a BUG() in Xen.2d