CVE-2026-4701 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 24, 2026
Firefox - Use After Free
Overview
Firefox < 149 and Firefox ESR < 140.9 contain a use-after-free vulnerability in the JavaScript Engine component, letting attackers cause memory corruption or remote code execution, exploit requires crafted web content.
Severity & Score
Impact
Attackers can cause memory corruption or execute arbitrary code remotely via crafted web content.
Mitigation
Update to Firefox 149, Firefox ESR 140.9 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-4701 - Critical (9.8) Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. š https://www.thehackerwire.com/vulnerability/CVE-2026-4701/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-4701
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- use_after_free
- Status
- modified
- EPSS
- 1.7%
- Social Posts
- 1
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H