CVE-2026-4702 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 25, 2026
Firefox - Remote Code Execution
Overview
Firefox < 149 and Firefox ESR < 140.9 contain a code execution vulnerability caused by JIT miscompilation in the JavaScript Engine, letting attackers execute arbitrary code, exploit requires crafted JavaScript code execution.
Severity & Score
Impact
Attackers can execute arbitrary code remotely via crafted JavaScript, potentially compromising the user's system.
Mitigation
Update to Firefox 149 or later and Firefox ESR 140.9 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-4702 - Critical (9.8) JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. š https://www.thehackerwire.com/vulnerability/CVE-2026-4702/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-4702
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- undefined
- Status
- modified
- EPSS
- 1.7%
- Social Posts
- 1
CWE
- CWE-843
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H