CVE-2026-84134: unauthenticated information disclosure in Mozilla Firefox

An unauthenticated remote attacker can obtain sensitive information from Mozilla Firefox, potentially leading to full confidentiality loss; this issue is tracked as CVE-2026-84134. The underlying weakness is classified as CWE-200 (exposure of sensitive information). The vendor has not listed affected releases in the supplied data, and no patch is recorded in the facts; the CVSS vector shows the flaw is exploitable over the network without privileges or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0057
CWE
CWE-200
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high urgency: the vulnerability scores 9.8 and the supplied facts show no available patch, so reduce exposure and prepare to apply vendor fixes as soon as they are released.

What is CVE-2026-84134?

An unauthenticated remote attacker can obtain sensitive information from Mozilla Firefox, potentially leading to full confidentiality loss; this issue is tracked as CVE-2026-84134. The underlying weakness is classified as CWE-200 (exposure of sensitive information). The vendor has not listed affected releases in the supplied data, and no patch is recorded in the facts; the CVSS vector shows the flaw is exploitable over the network without privileges or user interaction. The weakness is classified as CWE-200 (Exposure of Sensitive Information).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-84134 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-84134

  1. Isolate and restrict Firefox instances from untrusted networks and unneeded services.
  2. Monitor endpoints and network logs for unusual data exfiltration or sensitive-file access patterns.
  3. Apply vendor guidance and patches immediately when Mozilla releases them.
  4. Harden endpoint detection and response rules to flag abnormal browser activity and credential access.

Frequently asked questions

Is CVE-2026-84134 being actively exploited?

There are no public reports of exploitation of CVE-2026-84134 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-84134?

The supplied facts do not list specific affected Firefox versions, so treat all deployed Firefox instances as potentially at risk until Mozilla publishes an official affected-versions statement.

Is there a patch for CVE-2026-84134?

According to the provided facts, no patch is recorded as available for this vulnerability; apply vendor updates as soon as Mozilla issues them.

Does CVE-2026-84134 require authentication?

No authentication is required: the vulnerability is exploitable remotely without privileges or user interaction, per the provided CVSS vector.

References