CVE-2026-4698

critical
Published 2026-03-26 · Modified 2026-04-15
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

Important: thunderbird security update

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-6917.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:6917

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-6188.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2451006

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2451001

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-5930.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-5932.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450757

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450756

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450755

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450752

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450751

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450748

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450747

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450746

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450744

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450742

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450741

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450740

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450739

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450738

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450735

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450734

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450733

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450732

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450730

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450729

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450728

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450727

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450726

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450725

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450724

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450723

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450722

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450721

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450720

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450719

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450718

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450715

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450714

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450713

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450712

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450711

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2450710

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:5932

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-4698.html

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:5930

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:6188

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-4698

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-22/

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-21/

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-20/

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:6188

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:5930

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:5932

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component Red Hat statement Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux…

Description

firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10firefox-0:140.9.0-1.el10_1RHSA-2026:59312026-03-26T00:00:00Z
Red Hat Enterprise Linux 10thunderbird-0:140.9.0-1.el10_1RHSA-2026:63422026-04-01T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportfirefox-0:140.9.0-1.el10_0RHSA-2026:78432026-04-13T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportthunderbird-0:140.9.0-1.el10_0RHSA-2026:83152026-04-15T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportfirefox-0:140.9.0-1.el7_9RHSA-2026:84272026-04-16T00:00:00Z
Red Hat Enterprise Linux 8firefox-0:140.9.0-1.el8_10RHSA-2026:59322026-03-26T00:00:00Z
Red Hat Enterprise Linux 8thunderbird-0:140.9.0-1.el8_10RHSA-2026:69172026-04-07T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportfirefox-0:140.9.0-1.el8_2RHSA-2026:78402026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportthunderbird-0:140.9.0-1.el8_2RHSA-2026:82852026-04-15T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportfirefox-0:140.9.0-1.el8_4RHSA-2026:78582026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportthunderbird-0:140.9.0-1.el8_4RHSA-2026:88502026-04-20T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onfirefox-0:140.9.0-1.el8_4RHSA-2026:78582026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onthunderbird-0:140.9.0-1.el8_4RHSA-2026:88502026-04-20T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportfirefox-0:140.9.0-1.el8_6RHSA-2026:78422026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportthunderbird-0:140.9.0-1.el8_6RHSA-2026:82892026-04-15T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicefirefox-0:140.9.0-1.el8_6RHSA-2026:78422026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicethunderbird-0:140.9.0-1.el8_6RHSA-2026:82892026-04-15T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsfirefox-0:140.9.0-1.el8_6RHSA-2026:78422026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsthunderbird-0:140.9.0-1.el8_6RHSA-2026:82892026-04-15T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicefirefox-0:140.9.0-1.el8_8RHSA-2026:78382026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicethunderbird-0:140.9.0-1.el8_8RHSA-2026:82882026-04-15T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsfirefox-0:140.9.0-1.el8_8RHSA-2026:78382026-04-13T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsthunderbird-0:140.9.0-1.el8_8RHSA-2026:82882026-04-15T00:00:00Z
Red Hat Enterprise Linux 9firefox-0:140.9.0-1.el9_7RHSA-2026:59302026-03-26T00:00:00Z
Red Hat Enterprise Linux 9thunderbird-0:140.9.0-1.el9_7RHSA-2026:61882026-03-30T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsfirefox-0:140.9.0-1.el9_0RHSA-2026:78392026-04-13T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsthunderbird-0:140.9.0-1.el9_0RHSA-2026:82862026-04-15T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsfirefox-0:140.9.0-1.el9_2RHSA-2026:78412026-04-13T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsthunderbird-0:140.9.0-1.el9_2RHSA-2026:82872026-04-15T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportfirefox-0:140.9.0-1.el9_4RHSA-2026:78452026-04-13T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportthunderbird-0:140.9.0-1.el9_4RHSA-2026:82902026-04-15T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportfirefox-0:140.9.0-1.el9_6RHSA-2026:78372026-04-13T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportthunderbird-0:140.9.0-1.el9_6RHSA-2026:82842026-04-15T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10rhel10/firefox-flatpakAffected
Red Hat Enterprise Linux 10rhel10/thunderbird-flatpakAffected
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7thunderbirdOut of support scope

Apply commands

bash fix
Apply RHSA-2026:5931 for Red Hat Enterprise Linux 10
yum update -y firefox
# or:
dnf upgrade -y firefox

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 10Affected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
redhat rhel9fixed
debian debiansidfixed149.0-1
debian debianbookwormfixed140.9.0esr-1~deb12u1
debian debianbullseyefixed140.9.0esr-1~deb11u1
debian debianforkyfixed140.9.0esr-1
debian debiantrixiefixed140.9.0esr-1~deb13u1
rockylinux rocky9fixed
suse slesaffected

Application impact

VendorProductVersionsFixed
mozilla mozillafirefox{"endExcluding":"115.34.0"}115.34.0

References

CWEs

CWE-843

Verify integrity in audit chain (admin only). AS-IS.