Find notable cyber news and cases, enriched with sources, timelines, and signals.

Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer process. The vulnerable stable-release range spans Firefox 147 through 151.0.2, and Tor Browser releases built on those Firefox versions were also affected. Nebula Security says no extra user action was required beyond visiting the page. Public exploit material exists, but the available record does not establish in-the-wild user compromise.

Related Happenings

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

CISA KEV multi-product active exploitation wave (CVE-2020-7796)

Exploitation Wave
H score53 First: 18.02.2026 08:52 Last: 18.02.2026 08:52 Sources 1

About this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...

Timeline

  1. 29.07.2026 14:57 2 articles · 2h ago

    Malicious webpage can trigger Firefox JIT code execution

    Initial Disclosure

    Nebula Security said CVE-2026-10702 in Firefox can be triggered by simply visiting a malicious webpage with no additional user interaction, yielding arbitrary code execution in the browser's renderer process. Mozilla fixed the flaw in Firefox 151.0.3, and the same issue was said to affect Tor Browser releases built on vulnerable Firefox versions; the available record as of July 28, 2026 did not establish exploitation against users in the wild.

    Show sources