CVE-2026-4684
Mozilla Firefox, Thunderbird, Red Hat Enterprise Linux 10
Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- CVSS
- 7.5
- EPSS
- 0.35% 27.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.24