
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4694 is a high-severity vulnerability involving incorrect boundary conditions and integer overflow in the Graphics component of Mozilla Firefox and Thunderbird. It was discovered by researcher Sajeeb Lohani and disclosed on March 24, 2026, as part of Mozilla's coordinated security advisory release. Affected products include Firefox prior to version 149, Firefox ESR prior to 115.34, Firefox ESR prior to 140.9 (for the 128.x branch), Thunderbird prior to 149, and Thunderbird ESR prior to 140.9. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Mozilla Advisory mfsa2026-20, Mozilla Advisory mfsa2026-22).
The root cause is classified under CWE-190 (Integer Overflow or Wraparound) and CWE-754 (Improper Check for Unusual or Exceptional Conditions), manifesting as incorrect boundary checks combined with integer overflow in Firefox's Graphics rendering component (referenced internally as Bug 2018430). The vulnerability is network-exploitable with no authentication or user interaction required, suggesting it can be triggered through maliciously crafted graphical content processed by the browser or email client. The attack vector is remote (AV:N), with low complexity and no privileges required, making it straightforward to trigger in a browsing or email-rendering context. No public proof-of-concept code has been identified at this time (Mozilla Advisory mfsa2026-20, Mozilla Advisory mfsa2026-22).
The primary impact of CVE-2026-4694 is a denial-of-service condition, as the CVSS score reflects high availability impact with no confidentiality or integrity impact. Successful exploitation could cause the browser or email client to crash or become unresponsive when processing specially crafted graphical content. While the vulnerability is rated High severity, the scope is limited to the affected application process and does not directly enable code execution or data exfiltration based on currently available information (Mozilla Advisory mfsa2026-20, Feedly).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-4694 as of the available data. The EPSS score is approximately 0.008% (0.000080), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified. Detection coverage exists across multiple vulnerability scanners including Qualys and Nessus (Mozilla Advisory mfsa2026-20, Feedly).
Mozilla has released patched versions addressing CVE-2026-4694: Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9. Organizations should prioritize upgrading to these versions immediately, particularly for systems where Firefox or Thunderbird is used to process untrusted web content or emails. No configuration-based workarounds have been published; upgrading to a fixed version is the only recommended remediation (Mozilla Advisory mfsa2026-20, Mozilla Advisory mfsa2026-21, Mozilla Advisory mfsa2026-22).
The vulnerability was part of a large batch of security fixes released by Mozilla on March 24, 2026, covering Firefox 149 and associated ESR releases, which addressed over 37 vulnerabilities in total. Security news outlets such as CyberSecurityNews and HealSecurity covered the Firefox 149 release, highlighting the breadth of the patch batch. Downstream Linux distributions including Debian, Red Hat, AlmaLinux, Rocky Linux, openSUSE, and Amazon Linux 2 have issued their own security advisories and package updates incorporating these fixes (Mozilla Advisory mfsa2026-20).
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.9.0esr-1~deb12u1
sid
thunderbird: 1:140.9.0esr-1
trixie
thunderbird: 1:140.9.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."