CVE-2026-15719
published 2026-07-14CVE-2026-15719: We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in…
PriorityP428medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.34%
26.4th percentile
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 152.0.6 | Firefox 152.0.6 |
| mozilla | firefox | < 152.0.6 | 152.0.6 |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < Firefox ESR 140.13 | Firefox ESR 140.13 |
| mozilla | firefox_esr | < Firefox ESR 115.38 | Firefox ESR 115.38 |
| mozilla | thunderbird | < Thunderbird 140.13 | Thunderbird 140.13 |
| mozilla | thunderbird | — | — |
| rhel10 | firefox-flatpak | — | — |
| rhel10 | thunderbird-flatpak | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: thunderbird: Site isolation issue in the DOM: Navigation component
vendor_redhat·2026-07-14·CVSS 5.4
CVE-2026-15719 [MEDIUM] CWE-501 firefox: thunderbird: Site isolation issue in the DOM: Navigation component
firefox: thunderbird: Site isolation issue in the DOM: Navigation component
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/thunderbird-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: thunderbird (Red Hat Enterprise Linux 10) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: t
Mozilla
Mozilla Foundation Security Advisory 2026-70: CVE-2026-15719
vendor_mozilla·CVSS 5.4
CVE-2026-15719 [MEDIUM] Mozilla Foundation Security Advisory 2026-70: CVE-2026-15719
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-15719
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
Mozilla
Mozilla Foundation Security Advisory 2026-72: CVE-2026-15719
vendor_mozilla
CVE-2026-15719 Mozilla Foundation Security Advisory 2026-72: CVE-2026-15719
Mozilla Foundation Security Advisory 2026-72
CVE: CVE-2026-15719
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.13
Mozilla
Mozilla Foundation Security Advisory 2026-67: CVE-2026-15719
vendor_mozilla
CVE-2026-15719 Mozilla Foundation Security Advisory 2026-67: CVE-2026-15719
Mozilla Foundation Security Advisory 2026-67
CVE: CVE-2026-15719
Product: Firefox
Impact: critical
Fixed in: Firefox 152.0.6
Mozilla
Mozilla Foundation Security Advisory 2026-69: CVE-2026-15719
vendor_mozilla·CVSS 5.4
CVE-2026-15719 [MEDIUM] Mozilla Foundation Security Advisory 2026-69: CVE-2026-15719
Mozilla Foundation Security Advisory 2026-69
CVE: CVE-2026-15719
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.38
GHSA
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
ghsa_unreviewed·2026-07-14
CVE-2026-15719 [MEDIUM] We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15719 firefox: thunderbird: Site isolation issue in the DOM: Navigation component
bugzilla·2026-07-14·CVSS 5.4
CVE-2026-15719 [MEDIUM] CVE-2026-15719 firefox: thunderbird: Site isolation issue in the DOM: Navigation component
CVE-2026-15719 firefox: thunderbird: Site isolation issue in the DOM: Navigation component
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.
Hackernews
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
blogs_hackernews·2026-07-15·CVSS 4.3
CVE-2026-15718 [MEDIUM] Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities are listed below -
CVE-2026-15718 , an invalid pointer in the JavaScript: WebAssembly component
CVE-2026-15719 , a site isolation in the DOM: Navigation component
"We are aware that exploit code for this is public, however we are not aware of any attacks in the wild abusing this flaw," Mozilla said in an advisory. Both vulnerabilities have been addressed in Firefox version 152.0.6.
The release com
2026-07-14
Published