DIRAS TAKE
High priority: this is a remote, pre-auth code-execution issue (CVSS 9.8) and no patch is listed in the provided data, so immediately limit exposure and follow Mozilla mitigation guidance when available.
What is CVE-2026-84129?
Attackers on the network can run arbitrary code in Mozilla Firefox by exploiting a flaw in the browser’s DOM navigation/site-isolation handling (CVE-2026-84129). The supplied facts do not enumerate specific affected Firefox releases, and Mozilla’s fixed-release list is not included here; the CVSS vector shows exploitation requires only network access and no user interaction or privileges. Successful attacks could fully compromise the affected Firefox process, impacting confidentiality, integrity, and availability for users running vulnerable builds.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-84129 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84129
- Restrict Firefox access to untrusted sites using network filtering, web proxies, or browser policies.
- Apply any temporary mitigations recommended by Mozilla and follow their update guidance when published.
- Increase monitoring for unusual Firefox crashes, child-process launches, and suspicious network activity from browser endpoints.
- Prepare to deploy vendor updates immediately to prioritized hosts when Mozilla issues a patch.
Frequently asked questions
Is CVE-2026-84129 being actively exploited?
There are no public reports of exploitation of CVE-2026-84129 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-84129?
The provided facts do not list specific affected Firefox versions, so the exact affected releases are unknown from this data.
Is there a patch for CVE-2026-84129?
No patch is listed in the supplied data; patchAvailable is false in the facts provided.
Does CVE-2026-84129 require authentication?
No; the CVSS vector in the supplied data indicates no privileges and no user interaction are required for exploitation.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84129
- cve.org/CVERecord?id=CVE-2026-84129
- bugzilla.mozilla.org/show_bug.cgi?id=2055028
- mozilla.org/security/advisories/mfsa2026-82
- mozilla.org/security/advisories/mfsa2026-85
- mozilla.org/security/advisories/mfsa2026-86
- mozilla.org/security/advisories/mfsa2026-88
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026