Cyber Resilience

CVE-2026-4717

Mozilla Firefox ≤ 140.9.0

Published
24 March 2026
Modified
13 April 2026
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0042 35th percentile
Risk Priority 71 floored blend · peak EPSS

Summary

CVE-2026-4717 is a critical-severity an unspecified weakness vulnerability in Mozilla Firefox. Its CVSS base score is 9.8 (Critical).

Operationally, ranked at the 35th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2026-4717 is a privilege escalation vulnerability in the Netmonitor component affecting Mozilla Firefox prior to version 149, Firefox ESR prior to 140.9, Thunderbird prior to 149, and Thunderbird prior to 140.9. The issue has a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity with network accessibility, low attack complexity, and no requirements for privileges or user interaction.

Remote attackers require no authentication or privileges to exploit this vulnerability over the network. Successful exploitation enables high-impact compromise of confidentiality, integrity, and availability, allowing attackers to escalate privileges within affected applications and potentially gain unauthorized control over the victim's system.

Mozilla security advisories (MFSA 2026-20, 22, 23, and 24) and the associated Bugzilla entry detail the fix applied in the specified versions. Security practitioners should prioritize updating to Firefox 149, Firefox ESR 140.9, Thunderbird 149, or Thunderbird 140.9 to mitigate the vulnerability.

EU & UK References

Vulnerability Data

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-23604Same product: Mozilla Firefox
CVE-2023-25733Same product: Mozilla Firefox
CVE-2024-2606Same product: Mozilla Firefox
CVE-2026-4715Same product: Mozilla Firefox
CVE-2023-23600Same product: Mozilla Firefox
CVE-2026-8391Same product: Mozilla Firefox
CVE-2024-1554Same product: Mozilla Firefox
CVE-2026-24868Same product: Mozilla Firefox
CVE-2024-0745Same product: Mozilla Firefox
CVE-2025-13014Same product: Mozilla Firefox

Affected Assets

mozilla
firefox
≤ 140.9.0 · ≤ 149.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References