Incorrect boundary conditions in the Audio/Video component affecting Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
This out-of-bounds write vulnerability can be exploited remotely over the network without requiring user authentication or interaction. Successful exploitation could allow an attacker to achieve high confidentiality, integrity, and availability impacts, potentially leading to complete system compromise, data theft, data corruption, or denial of service.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patches are available. Update to Firefox 149 or later, Firefox ESR 140.9 or later, Thunderbird 149 or later, or Thunderbird ESR 140.9 or later.
Immediately prioritize patching systems running vulnerable versions of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. Apply the available patches as soon as possible given the critical severity (CVSS 9.8). Until patches can be applied, consider restricting access to untrusted audio/video content and limiting network exposure of affected applications.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD published the first details for CVE-2026-4710
Feedly found the first article mentioning CVE-2026-4710 . See article
Detection for the vulnerability has been added to Qualys ( 386905 386906 )
Detection for the vulnerability has been added to Nessus ( 303556 )
RedHat CVE advisory released a security advisory ( CVE-2026-4710 ) .
A CVSS base score of 6.1 has been assigned.
A CVSS base score of 9.8 has been assigned.
Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks
Slackware 15.0 Firefox Security Notice SSA-2026-083-03 Needed
openSUSE-SU-2026:10413-1: moderate: firefox-esr-140.9.0-1.1 on GA media
Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks
Linux Distros Unpatched Vulnerability : CVE-2026-4710
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
