Mozilla disclosed two high-severity privilege escalation vulnerabilities affecting Firefox versions earlier than 149, including CVE-2026-4722 in the IPC component and CVE-2026-4717 in the Netmonitor component. The Netmonitor flaw also affects Firefox ESR versions earlier than 140.9.0. Both issues were formally published with Mozilla advisories and Bugzilla references, marking coordinated vendor disclosure and public tracking.
NVD analysis rated both bugs as high impact to confidentiality, integrity, and availability. CVE-2026-4717 received a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-exploitable privilege escalation without user interaction, while CVE-2026-4722 was assigned AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, requiring user interaction. Mozilla linked the disclosures to security advisories including MFSA-2026-20 and MFSA-2026-22, and organizations using Firefox or Firefox ESR should prioritize updates to supported fixed versions.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Mozilla published CVE-2026-4723, a use-after-free flaw in the JavaScript Engine affecting Firefox versions earlier than 149.0, with references to a Bugzilla entry and MFSA-2026-20. NVD issued its initial analysis the same day, classifying it as CWE-416 and assigning a critical CVSS v3.1 vector indicating remote exploitation with high impact.
Mozilla recorded CVE-2026-4725, a use-after-free vulnerability in the Graphics: Canvas2D component that can lead to a sandbox escape, affecting Firefox versions earlier than 149. NVD published its initial analysis the same day, classifying it as CWE-416 and assigning a high-severity CVSS v3.1 vector.
Mozilla published CVE-2026-4715, an uninitialized memory flaw in the Graphics: Canvas2D component affecting Firefox versions earlier than 149.0 and Firefox ESR versions earlier than 140.9.0. NVD published its initial analysis the same day, assigning a high-severity CVSS v3.1 vector and classifying the issue as CWE-908.
On the same day as disclosure, NVD added its initial analysis for CVE-2026-4717 with a high-severity CVSS v3.1 score, while the CVE-2026-4722 record was updated to include a CVSS v3.1 vector indicating high impact. These updates formalized severity assessment for both Mozilla privilege escalation flaws.
Mozilla formally disclosed CVE-2026-4722, a privilege escalation vulnerability in the Firefox IPC component affecting versions earlier than 149. The record added references to a Mozilla Bugzilla entry and a Mozilla security advisory for tracking and remediation.
Mozilla published CVE-2026-4717, a privilege escalation flaw in the Netmonitor component affecting Firefox versions earlier than 149.0 and Firefox ESR versions earlier than 140.9.0. The disclosure included references to Bugzilla and Mozilla security advisories MFSA-2026-20 and MFSA-2026-22.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.