DIRAS TAKE
Treat this as urgent: the flaw affects a browser component and the CVSS score is 9.8, and there is no patch available in the provided facts — prioritize exposure reduction and monitoring immediately.
What is CVE-2026-84133?
Remote attackers can bypass site isolation in Firefox's DOM Push Subscriptions component, potentially exposing cross-origin data and allowing full compromise of confidentiality, integrity, and availability; this issue is tracked as CVE-2026-84133. The vendor description identifies the flaw in the DOM Push Subscriptions area of Firefox (and related Mozilla products) but this dataset does not list concrete affected version numbers. According to the CVSS vector, exploitation requires only network access and no privileges or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-84133 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-84133
- Follow Mozilla's official guidance and install fixes as soon as the vendor publishes them.
- Limit exposure by restricting access to untrusted sites and extensions that use Push Subscriptions where possible.
- Monitor browser telemetry and endpoint logs for abnormal cross-origin activity and signs of compromise.
- Block or restrict network paths for untrusted content from managed devices until a vendor patch is available.
Frequently asked questions
Is CVE-2026-84133 being actively exploited?
There are no public reports of active exploitation or public exploit code for CVE-2026-84133 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-84133?
The vendor description identifies the issue in the DOM Push Subscriptions component of Firefox, but this dataset does not list specific affected Firefox version numbers.
Is there a patch for CVE-2026-84133?
According to the provided facts, no patch is available for CVE-2026-84133 in this dataset; apply vendor guidance and install updates when Mozilla releases them.
Does CVE-2026-84133 require authentication?
No — the CVSS vector indicates no privileges or user interaction are required to exploit this issue in Firefox.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84133
- cve.org/CVERecord?id=CVE-2026-84133
- bugzilla.mozilla.org/show_bug.cgi?id=2032388
- mozilla.org/security/advisories/mfsa2026-82
- mozilla.org/security/advisories/mfsa2026-85
- mozilla.org/security/advisories/mfsa2026-86
- mozilla.org/security/advisories/mfsa2026-88
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026