Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-16390: Firefox Enterprise Policies Bypassed, Updates Required
CVE-2026-16390
CVE-2026-16390
Summary
A security issue in Firefox's Enterprise Policies component could allow attackers to bypass security settings. This affects organizations using Firefox for business purposes. To protect your system, update to the latest version of Firefox or Firefox ESR.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | All versions |
Original title
Mitigation bypass in the Enterprise Policies component
Original description
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Vulnerability type
CWE-693
Protection Mechanism Failure
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026