Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-16390: Firefox Enterprise Policies Bypassed, Updates Required

CVE-2026-16390 CVE-2026-16390
Summary

A security issue in Firefox's Enterprise Policies component could allow attackers to bypass security settings. This affects organizations using Firefox for business purposes. To protect your system, update to the latest version of Firefox or Firefox ESR.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
mozilla firefox All versions
Original title
Mitigation bypass in the Enterprise Policies component
Original description
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Vulnerability type
CWE-693 Protection Mechanism Failure
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026