Mozilla fixes a file-handling mitigation bypass in Firefox 157.0.1 (CVE-2026-106016)
Mozilla has released Firefox 157.0.1 to fix CVE-2026-106016, a flaw that allows attackers to bypass mitigations in the browser's file handling component. It affects Firefox users and the update is already available.
What happened
On 6 October 2026 Mozilla published security advisory MFSA2026-104, covering a single vulnerability in the Firefox browser: CVE-2026-106016, described as a mitigation bypass in the File Handling component.
According to Mozilla's advisory, the issue is resolved in Firefox 157.0.1, and the vendor rates its impact as moderate. The related technical report (Bugzilla bug 2067465) remains restricted, a common practice at Mozilla in the days following a release so as not to expose details that would help build an attack.
One discrepancy is worth flagging: the entry published in the NVD database scores this vulnerability at CVSS 9.8 (critical), with a network attack vector and no privileges or user interaction required. Mozilla, as the vendor, classifies it as moderate. Where the two disagree the vendor's assessment prevails, but the gap is wide enough to justify treating the update as a priority.
Who is affected
This affects users and organisations running Firefox versions earlier than 157.0.1. Mozilla's advisory does not specify which exact versions are vulnerable, nor whether other products in the family (ESR builds or Thunderbird, for example) are impacted; it refers only to Firefox and the fixed version.
- Mozilla Firefox: update to version 157.0.1 or later.
- Managed Firefox deployments (corporate fleets, classrooms, kiosks) where automatic updates are disabled or held back.
Exploitation status
CVE-2026-106016 is not listed in CISA's KEV catalogue, so there is no official record of active exploitation. No public exploit code is known either.
FIRST estimates the probability of exploitation over the next 30 days at 0.1 %, a very low figure (3rd percentile among all known vulnerabilities). Even so, given the critical score assigned in NVD and the fact that browser flaws are typically triggered through malicious web pages or files, the update should not be postponed.
What to do
The fix is straightforward and no additional mitigation is required: update the browser. Mozilla's advisory does not offer any temporary workaround.
- Update Firefox to version 157.0.1 on all machines (Help > About Firefox forces an update check).
- Confirm that automatic updates are enabled and that no corporate policy is blocking them.
- In managed environments, push version 157.0.1 through your usual software deployment tool and then verify the version inventory.
- Remind users to restart the browser: the update only completes once Firefox is closed and reopened.
- If you run ESR channels or other Firefox-based products, check the relevant Mozilla advisories, as MFSA2026-104 makes no statement about them.
Sources
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2026-106016 | Critical (9.8) | — | 10/6/2026 | Analyzed |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.