CVE-2026-4720
published 2026-03-24CVE-2026-4720: Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.42%
34.5th percentile
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 149.0-1 (sid) | firefox 149.0-1 (sid) |
| debian | firefox-esr | < firefox 149.0-1 (sid) | firefox 149.0-1 (sid) |
| debian | thunderbird | < firefox 149.0-1 (sid) | firefox 149.0-1 (sid) |
| mozilla | firefox | < 140.9.0 | 140.9.0 |
| mozilla | firefox | < 149.0 | 149.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 140.9.0 | 140.9.0 |
| mozilla | thunderbird | < 149.0 | 149.0 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb11u1 | 1:140.9.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb12u1 | 1:140.9.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1~deb13u1 | 1:140.9.0esr-1~deb13u1 |
| mozilla | thunderbird | >= 0 < 1:140.9.0esr-1 | 1:140.9.0esr-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 148 memory corruption (Nessus ID 303907)
vuldb·2026-07-01·CVSS 9.8
CVE-2026-4720 [CRITICAL] Mozilla Firefox up to 148 memory corruption (Nessus ID 303907)
A vulnerability classified as critical has been found in Mozilla Firefox up to 148. This impacts an unknown function. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2026-4720. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
OSV
CVE-2026-4720: Memory safety bugs present in Firefox ESR 140
osv·2026-03-24·CVSS 9.8
CVE-2026-4720 [CRITICAL] CVE-2026-4720: Memory safety bugs present in Firefox ESR 140
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
GHSA
GHSA-h6r3-p5gv-5qgc: Memory safety bugs present in Firefox ESR 140
ghsa_unreviewed·2026-03-24
CVE-2026-4720 [CRITICAL] CWE-120 GHSA-h6r3-p5gv-5qgc: Memory safety bugs present in Firefox ESR 140
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149 and Firefox ESR < 140.9.
Red Hat
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
vendor_redhat·2026-03-24·CVSS 9.8
CVE-2026-4720 [CRITICAL] CWE-120 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with
Debian
CVE-2026-4720: firefox - Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox ...
vendor_debian·2026·CVSS 9.8
CVE-2026-4720 [CRITICAL] CVE-2026-4720: firefox - Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox ...
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
Mozilla
Mozilla Foundation Security Advisory 2026-23: CVE-2026-4720
vendor_mozilla·CVSS 9.8
CVE-2026-4720 [CRITICAL] Mozilla Foundation Security Advisory 2026-23: CVE-2026-4720
Mozilla Foundation Security Advisory 2026-23
CVE: CVE-2026-4720
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 149
Mozilla
Mozilla Foundation Security Advisory 2026-24: CVE-2026-4720
vendor_mozilla·CVSS 9.8
CVE-2026-4720 [CRITICAL] Mozilla Foundation Security Advisory 2026-24: CVE-2026-4720
Mozilla Foundation Security Advisory 2026-24
CVE: CVE-2026-4720
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.9
Mozilla
Mozilla Foundation Security Advisory 2026-20: CVE-2026-4720
vendor_mozilla·CVSS 9.8
CVE-2026-4720 [CRITICAL] Mozilla Foundation Security Advisory 2026-20: CVE-2026-4720
Mozilla Foundation Security Advisory 2026-20
CVE: CVE-2026-4720
Product: Firefox
Impact: high
Fixed in: Firefox 149
Mozilla
Mozilla Foundation Security Advisory 2026-22: CVE-2026-4720
vendor_mozilla·CVSS 9.8
CVE-2026-4720 [CRITICAL] Mozilla Foundation Security Advisory 2026-22: CVE-2026-4720
Mozilla Foundation Security Advisory 2026-22
CVE: CVE-2026-4720
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.9
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32776 [MEDIUM] CVE-2026-32776 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32776 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat-devel
firefox-debugsource
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 20, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity
Wiz
CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-25210 [MEDIUM] CVE-2026-25210 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25210 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
Source : NVD
## 7.8
Score
Published January 30, 2026
Severity HIGH
CNA Score 6.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxmltok
libexpat1
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Feb 04, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity MEDIUM
Wiz
ELSA-2026-1240 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1240 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1240 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1240: fence-agents security update (IMPORTANT)
Source : NVD
Published January 27, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
fence-agents-compute
fence-agents-eps
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-20
Wiz
ELSA-2026-0991 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-0991 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-0991 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-0991: glib2 security update (MODERATE)
Source : NVD
Published January 22, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
glib2
glib2-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
Ni
Wiz
ELSA-2025-23141 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2025-23141 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23141 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2025-23141: ruby security update (MODERATE)
Source : NVD
Published December 11, 2025
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
rubygem-minitest
rubygem-rbs
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRIT
Wiz
ELSA-2026-1592 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1592 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1592 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1592: iperf3 security update (MODERATE)
Source : NVD
Published January 29, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
iperf3
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
NixOS
Mozill
Wiz
ELSA-2026-0126 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-0126 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-0126 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-0126: poppler security update (MODERATE)
Source : NVD
Published January 6, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
poppler-cpp
poppler-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
Wiz
ELSA-2025-23139 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2025-23139 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2025-23139 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2025-23139: libsoup3 security update (MODERATE)
Source : NVD
Published December 11, 2025
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsoup3
libsoup3-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITI
Wiz
ELSA-2026-1595 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1595 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1595 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1595: iperf3 security update (MODERATE)
Source : NVD
Published January 29, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
iperf3
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
NixOS
Mozill
Wiz
CVE-2026-21991 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21991 [MEDIUM] CVE-2026-21991 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21991 :
Linux Oracle vulnerability analysis and mitigation
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dtrace
dtrace-devel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV
Wiz
CVE-2026-24515 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-24515 [LOW] CVE-2026-24515 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24515 :
Alma Linux vulnerability analysis and mitigation
In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
Source : NVD
## 2.5
Score
Published January 23, 2026
Severity LOW
CNA Score 2.9
Affected Technologies
Alma Linux
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mingw-expat
libexpat1-32bit
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Severity LOW Has Fix Added at: Feb 04, 2026
Alpine edge Severity LOW Has Fix Added at: Feb 03, 2026
CBL-Mariner 2.0 Severity LOW Has Fix Added at: Feb 08, 2026
CBL-Mariner 3.0 Severity LOW Has
Wiz
CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.9
CVE-2026-32778 [LOW] CVE-2026-32778 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32778 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 2.9
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
thunderbird
libexpat-devel
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar
Wiz
ELSA-2026-1518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1518 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1518 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1518: grafana-pcp security update (IMPORTANT)
Source : NVD
Published January 28, 2026
Severity HIGH
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
grafana-pcp
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4721
CRITICAL
9.8
NixO
Wiz
CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-32777 [MEDIUM] CVE-2026-32777 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32777 :
Alma Linux vulnerability analysis and mitigation
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Source : NVD
## 5.5
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libexpat1
seal-expat
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 19, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 17, 2026
Echo Severity MEDIUM Has Fix Added at: Mar 17, 2026
Red
Wiz
ELSA-2026-1380 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1380 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1380 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1380: osbuild-composer security update (MODERATE)
Source : NVD
Published January 28, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
osbuild-composer-core
osbuild-composer-worker
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published
Wiz
ELSA-2026-1852 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
[MEDIUM] ELSA-2026-1852 Impact, Exploitability, and Mitigation Steps | Wiz
## ELSA-2026-1852 :
Linux Oracle vulnerability analysis and mitigation
ELSA-2026-1852: util-linux security update (MODERATE)
Source : NVD
Published February 4, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Oracle
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libsmartcols-devel
util-linux-user
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Oracle vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-4
Wiz
CVE-2026-4720 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-4720 [CRITICAL] CVE-2026-4720 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4720 :
NixOS vulnerability analysis and mitigation
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Source : NVD
## 9.8
Score
Published March 24, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:mo
Wiz
CVE-2026-4177 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4177 [MEDIUM] CVE-2026-4177 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4177 :
Alma Linux vulnerability analysis and mitigation
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.
The heap overflow occurs when class names exceed the initial 512-byte allocation.
The base64 decoder could read past the buffer end on trailing newlines.
strtok mutated n->type_id in place, corrupting shared node data.
A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
Source : NVD
## 9.1
Score
Published March 16, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Alma Linux
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Dat
Bugzilla
CVE-2026-4720 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
bugzilla·2026-03-24·CVSS 9.8
CVE-2026-4720 [CRITICAL] CVE-2026-4720 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVE-2026-4720 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149 and Firefox ESR < 140.9.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:5931 https://access.redhat.com/errata/RHSA-2026:5931
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:5930 https://access.redhat.com/errata/RHSA-2026:5930
---
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2004652%2C2019372%2C2021922%2C2022567%2C2022733https://www.mozilla.org/security/advisories/mfsa2026-20/https://www.mozilla.org/security/advisories/mfsa2026-22/https://www.mozilla.org/security/advisories/mfsa2026-23/https://www.mozilla.org/security/advisories/mfsa2026-24/https://access.redhat.com/errata/RHSA-2026:5930https://access.redhat.com/errata/RHSA-2026:5931https://access.redhat.com/errata/RHSA-2026:5932https://access.redhat.com/errata/RHSA-2026:6188https://access.redhat.com/errata/RHSA-2026:6342https://access.redhat.com/errata/RHSA-2026:6917https://access.redhat.com/errata/RHSA-2026:7837https://access.redhat.com/errata/RHSA-2026:7838https://access.redhat.com/errata/RHSA-2026:7839https://access.redhat.com/errata/RHSA-2026:7840https://access.redhat.com/errata/RHSA-2026:7841https://access.redhat.com/errata/RHSA-2026:7842https://access.redhat.com/errata/RHSA-2026:7843https://access.redhat.com/errata/RHSA-2026:7845https://access.redhat.com/errata/RHSA-2026:7858https://access.redhat.com/errata/RHSA-2026:8284https://access.redhat.com/errata/RHSA-2026:8285https://access.redhat.com/errata/RHSA-2026:8286https://access.redhat.com/errata/RHSA-2026:8287https://access.redhat.com/errata/RHSA-2026:8288https://access.redhat.com/errata/RHSA-2026:8289https://access.redhat.com/errata/RHSA-2026:8290https://access.redhat.com/errata/RHSA-2026:8315https://access.redhat.com/errata/RHSA-2026:8427https://access.redhat.com/errata/RHSA-2026:8850https://access.redhat.com/security/cve/CVE-2026-4720https://bugzilla.redhat.com/show_bug.cgi?id=2450751https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4720.json
2026-03-24
Published