<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-4685 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-4685/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 24 Mar 2026 13:16:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-4685/feed.xml" rel="self" type="application/rss+xml"/><item><title>Mozilla Firefox Canvas2D Improper Boundary Condition Vulnerability (CVE-2026-4685)</title><link>https://feed.craftedsignal.io/briefs/2026-03-firefox-canvas2d-vuln/</link><pubDate>Tue, 24 Mar 2026 13:16:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-firefox-canvas2d-vuln/</guid><description>An improper boundary condition vulnerability in the Canvas2D component of Mozilla Firefox, Firefox ESR, and Thunderbird (CVE-2026-4685) could allow for a denial-of-service condition.</description><content:encoded>&lt;p>CVE-2026-4685 describes an incorrect boundary condition in the Graphics: Canvas2D component affecting Mozilla Firefox versions prior to 149, Firefox ESR versions prior to 115.34 and 140.9, and Thunderbird versions prior to 149 and 140.9. This vulnerability could be exploited by a remote attacker to cause a denial-of-service condition. Successful exploitation of this vulnerability could result in the application crashing or becoming unresponsive. The vulnerability was reported and patched by…&lt;/p>
</content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>cve-2026-4685</category><category>firefox</category><category>thunderbird</category><category>denial-of-service</category><category>canvas2d</category></item></channel></rss>