Critical Vulnerabilities in Firefox and Thunderbird Require Immediate Patching
ID: 8cf0f6f8-513f-50a8-837d-7224797ecb79
STIX ID: report--8cf0f6f8-513f-50a8-837d-7224797ecb79
Feed Name: ThreatCluster
Multiple critical memory-safety vulnerabilities (CVE-2026-4720, CVE-2026-4710, CVE-2026-4705) were disclosed for Firefox and Thunderbird on March 24, 2026; they allow remote, no-user-interaction exploitation leading to potential full system compromise (CVSS 9.8). Affected versions include Firefox <149 and Thunderbird <149 (ESR <140.9); patches are available and immediate updates to Firefox 149 / Thunderbird 149 or later are strongly recommended. No public proof-of-concept or active exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
