CVE-2026-12295
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunde
CVSS
9.6
Crítico
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Publicado: 16 jun 2026 · Última mod.: 15 jul 2026 · CWE-693 · CWE-653
0.4%EPSS · 30 días0.4%
2026-06-302026-07-21
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2040160
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-57/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-58/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-59/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-60/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-61/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27717
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27733
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27734
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:29940
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30846
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33445
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36100
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36101
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36102
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:36103
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:37210
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:37391
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:38506
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:38750
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-464036.3 MED—
——0Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOnly(true)`, executes the destination context, and then restores the previous read-only state. However, the indirect contract delete and upgrade paths do not reject execution when `runtime.ReadOnly()` is true. As a result, a contract reached through read-only execution can call the production delete hook for a target contract it owns. The delete path appends the target address to `vmOutput.DeletedAccounts`, the output context merges `DeletedAccounts` into the caller output, and the smart contract processor later processes the VM output by deleting accounts listed in that field. The root cause is that read-only mode is applied as runtime state, but not enforced by the state-changing delete and upgrade host-core paths. This breaks the expected isolation boundary for workflows that rely on read-only calls to inspect another contract without allowing that callee to produce state-changing VM output. The issue is fixed in v1.7.17. Contract delete and upgrade host-core paths now reject execution when `runtime.ReadOnly()` is true. The invariant is regression-tested for delete, upgrade, storage writes, value transfers, and any VM output field that can later mutate chain state.7hCVE-2026-565853.1 BAJ—
——0HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.1dCVE-2026-473929.9 CRÍ—
——0PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be extracted via `vars()` and runtime string construction. This achieves arbitrary OS command execution on the host, completely defeating the sandbox. This is a novel bypass that survives all patches for CVE-2026-39888 (frame traversal), CVE-2026-34938 (str subclass), and CVE-2026-40158 (`type.__getattribute__` trampoline). PraisonAI version 4.6.40 and praisonaiagents version 1.6.40 contain an updated fix.1dCVE-2026-164069.1 CRÍ—
——0Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.1dCVE-2026-163949.1 CRÍ—
——0Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.1dCVE-2026-163709.1 CRÍ—
——0Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.5h