CVE-2026-4702 is a critical JIT miscompilation vulnerability found in the JavaScript Engine component of Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 149 and 140.9 respectively. This flaw is rated 9.8 Critical on the CVSS scale, indicating it can be exploited remotely with low attack complexity and no user interaction or privileges required, potentially leading to a complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog. Despite minimal community discussion and a very low EPSS score, the severe potential impact necessitates prompt patching of affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.