logo

Critical Vulnerabilities in Firefox and Thunderbird Require Immediate Patching

ID: 8cf0f6f8-513f-50a8-837d-7224797ecb79

STIX ID: report--8cf0f6f8-513f-50a8-837d-7224797ecb79

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-03-25

Date Updated: 2026-03-31

...
...

Multiple critical memory-safety vulnerabilities (CVE-2026-4720, CVE-2026-4710, CVE-2026-4705) were disclosed for Firefox and Thunderbird on March 24, 2026; they allow remote, no-user-interaction exploitation leading to potential full system compromise (CVSS 9.8). Affected versions include Firefox <149 and Thunderbird <149 (ESR <140.9); patches are available and immediate updates to Firefox 149 / Thunderbird 149 or later are strongly recommended. No public proof-of-concept or active exploitation has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.