« All news

AlertCritical

Mozilla fixes a file-handling mitigation bypass in Firefox 157.0.1 (CVE-2026-106016)

Mozilla has released Firefox 157.0.1 to fix CVE-2026-106016, a flaw that allows attackers to bypass mitigations in the browser's file handling component. It affects Firefox users and the update is already available.

What happened

On 6 October 2026 Mozilla published security advisory MFSA2026-104, covering a single vulnerability in the Firefox browser: CVE-2026-106016, described as a mitigation bypass in the File Handling component.

According to Mozilla's advisory, the issue is resolved in Firefox 157.0.1, and the vendor rates its impact as moderate. The related technical report (Bugzilla bug 2067465) remains restricted, a common practice at Mozilla in the days following a release so as not to expose details that would help build an attack.

One discrepancy is worth flagging: the entry published in the NVD database scores this vulnerability at CVSS 9.8 (critical), with a network attack vector and no privileges or user interaction required. Mozilla, as the vendor, classifies it as moderate. Where the two disagree the vendor's assessment prevails, but the gap is wide enough to justify treating the update as a priority.

Who is affected

This affects users and organisations running Firefox versions earlier than 157.0.1. Mozilla's advisory does not specify which exact versions are vulnerable, nor whether other products in the family (ESR builds or Thunderbird, for example) are impacted; it refers only to Firefox and the fixed version.

Exploitation status

CVE-2026-106016 is not listed in CISA's KEV catalogue, so there is no official record of active exploitation. No public exploit code is known either.

FIRST estimates the probability of exploitation over the next 30 days at 0.1 %, a very low figure (3rd percentile among all known vulnerabilities). Even so, given the critical score assigned in NVD and the fact that browser flaws are typically triggered through malicious web pages or files, the update should not be postponed.

What to do

The fix is straightforward and no additional mitigation is required: update the browser. Mozilla's advisory does not offer any temporary workaround.

Sources

Affected technologies

Mozilla Firefox

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-106016Critical (9.8)—10/6/2026Analyzed

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.