CVE-2024-9680Active Exploitation(debian / debian_linux)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-11-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • firefox
  • thunderbird

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
debian_linuxfirefoxthunderbird

2 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-04-22: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-04-22: 1Technical Details · 2026-01-29: 1Technical Details · 2026-04-22: 101-2904-22
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • kokumօtօ@__kokumoto
    Active Exploitation

    以下の4脆弱性がランサムウェアに悪用されたことが確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。 - Windowsの権限昇格CVE-2024-49039, CVE-2024-30088 - CyberPanelの無認証root権限RCE CVE-2024-51567 - FirefoxのRCE CVE-2024-9680 https://t.co/rE32uwR7pJ

    Post summary

    The post confirms that four CVEs, including Windows privilege escalation and RCEs in CyberPanel and Firefox, were actively exploited by ransomware, as per an updated CISA known‑exploited vulnerability catalog.

    06038163.4K
    7.2K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals APT actors chained Firefox browser exploit (CVE-2024-9680) with Windows Task Scheduler privilege escalation (CVE-2024-49039) for full system compromise. Attackers then moved laterally through misconfigured internal services before deploying ransomware. Runtime segmentation helps contain such post-compromise lateral movement. #ThreatIntel 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/exploit-chain-analysis-apt-espionage-2026

    Post summary

    The post reports that APT actors actively exploited CVE‑2024‑9680 and CVE‑2024‑49039 in a chained attack, but does not provide any PoC, exploit code, or patch information.

    0000075
    1.9K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird131.0--

Explore more