CVE-2026-84129: pre-auth remote code execution in Mozilla Firefox

Attackers on the network can run arbitrary code in Mozilla Firefox by exploiting a flaw in the browser’s DOM navigation/site-isolation handling (CVE-2026-84129). The supplied facts do not enumerate specific affected Firefox releases, and Mozilla’s fixed-release list is not included here; the CVSS vector shows exploitation requires only network access and no user interaction or privileges. Successful attacks could fully compromise the affected Firefox process, impacting confidentiality, integrity, and availability for users running vulnerable builds.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00291
CWE
CWE-346
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High priority: this is a remote, pre-auth code-execution issue (CVSS 9.8) and no patch is listed in the provided data, so immediately limit exposure and follow Mozilla mitigation guidance when available.

What is CVE-2026-84129?

Attackers on the network can run arbitrary code in Mozilla Firefox by exploiting a flaw in the browser’s DOM navigation/site-isolation handling (CVE-2026-84129). The supplied facts do not enumerate specific affected Firefox releases, and Mozilla’s fixed-release list is not included here; the CVSS vector shows exploitation requires only network access and no user interaction or privileges. Successful attacks could fully compromise the affected Firefox process, impacting confidentiality, integrity, and availability for users running vulnerable builds.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-84129 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-84129

  1. Restrict Firefox access to untrusted sites using network filtering, web proxies, or browser policies.
  2. Apply any temporary mitigations recommended by Mozilla and follow their update guidance when published.
  3. Increase monitoring for unusual Firefox crashes, child-process launches, and suspicious network activity from browser endpoints.
  4. Prepare to deploy vendor updates immediately to prioritized hosts when Mozilla issues a patch.

Frequently asked questions

Is CVE-2026-84129 being actively exploited?

There are no public reports of exploitation of CVE-2026-84129 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-84129?

The provided facts do not list specific affected Firefox versions, so the exact affected releases are unknown from this data.

Is there a patch for CVE-2026-84129?

No patch is listed in the supplied data; patchAvailable is false in the facts provided.

Does CVE-2026-84129 require authentication?

No; the CVSS vector in the supplied data indicates no privileges and no user interaction are required for exploitation.

References