CVE-2026-4698Disclosure(mozilla / firefox)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843CWE-733

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-02); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
firefox

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-04: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 103-2403-2504-0204-0304-04
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-241
General1
2026-03-251
Disclosure1
2026-04-022
Disclosure1Patch1
2026-04-031
Disclosure1
2026-04-041
Patch1
Full discourse6 posts
  • xvonfers@xvonfers
    Patch

    For some reason, it seemed to me that I had published, but it seemed to have forgotten👀 (CVE-2026-4698)[2020906][IonMonkey/IonAnalysis]JIT miscompilation/Type Confusion -> RCE https://hg-edge.mozilla.org/mozilla-central/rev/81f2dd7c9d474e765bf167801120034e0f4ef082 https://github.com/mozilla-firefox/firefox/commit/0629c75d9760cd85e8b5966fc8b2ebfc5bcc042a https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/#CVE-2026-4698 Reported by @maxpl0it

    Post summary

    The post references CVE-2026‑4698, a JIT miscompilation leading to RCE, and links to the Mozilla security advisory and code commit, but provides no PoC, exploit code, or evidence of active exploitation.

    07037203.4K
    5.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Patch

    ‼️ CVE-2026-4698: JIT miscompilation in Firefox's JavaScript Engine CVSS: 8.8 Affected versions: → Firefox < 149 → Firefox ESR < 115.34 / < 140.9 → Thunderbird < 149 / < 140.9 Credit: @maxpl0it via Trend Micro ZDI Patch now: https://www.mozilla.org/security/advisories/mfsa2026-20/ https://t.co/r1AnYUvcDX

    Post summary

    Mozilla has released a patch for CVE-2026-4698, a JIT miscompilation that affects older Firefox and Thunderbird versions, and the advisory is linked in the text.

    0402674.9K
    218.4K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-252|CVE-2026-4698] Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability (CVSS 8.8; Credit: maxpl0it) https://www.zerodayinitiative.com/advisories/ZDI-26-252/

    Post summary

    The advisory announces a type‑confusion remote code execution vulnerability in Firefox IonMonkey (CVE‑2026‑4698) with a CVSS score of 8.8, but does not provide PoC, exploit code, or patch details.

    0201152.1K
    5.5K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability (CVE-2026-4698) #CVE20264698 #CyberSecurity #MozillaFirefox #RemoteCodeExecutionVulnerability https://www.systemtek.co.uk/?p=48985 https://t.co/oLGKDIakm8

    Post summary

    A tweet announces the discovery of a type confusion remote code execution vulnerability (CVE‑2026‑4698) in Firefox's IonMonkey JIT, mentioning the CVE but providing no PoC, exploit, or patch details.

    0010076
    1.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4698 - Critical JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderb... https://www.thehackerwire.com/vulnerability/CVE-2026-4698/ https://t.co/BPzCVPhr1h

    Post summary

    A new critical JIT miscompilation vulnerability (CVE‑2026‑4698) in Mozilla’s JavaScript engine has been disclosed, affecting specified Firefox and Thunderbird versions.

    0000062
    145 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4698 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9. https://www.cve.org/CVERecord?id=CVE-2026-4698

    Post summary

    The post notes a JIT miscompilation vulnerability in Firefox's JavaScript engine, lists affected versions, but provides no PoC, exploit, or patch details.

    00000114
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---

Explore more