DIRAS TAKE
Urgent: this is a critical, pre-auth remote code execution with no patch listed in the facts; immediately reduce exposure for internet-facing Firefox installs and prepare to apply vendor updates as soon as they are published.
What is CVE-2026-84135?
Remote attackers can execute arbitrary code in Mozilla Firefox due to an input validation vulnerability (CVE-2026-84135). The flaw requires only network access and does not require authentication or user interaction, enabling exploitation across exposed Firefox instances. The vulnerability is mapped to CWE-20 and carries a CVSS 3.1 score of 9.8, indicating complete confidentiality, integrity, and availability impact if exploited. Vendor guidance and specific affected-version details are not present in the provided facts.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-84135 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84135
- Restrict network exposure of Firefox endpoints and block access to untrusted sites at network edge.
- Enable automatic updates for Firefox and apply the vendor's security updates immediately when released.
- Harden host configurations: use sandboxing, least-privilege policies, and endpoint isolation for users running Firefox.
- Monitor logs and intrusion-detection alerts for anomalous browser activity and indicators of compromise related to remote code execution.
Frequently asked questions
Is CVE-2026-84135 being actively exploited?
There are no public reports of active exploitation of CVE-2026-84135 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-84135?
The provided facts do not list specific affected Firefox versions or a vendor-supplied affected-versions range.
Is there a patch for CVE-2026-84135?
No patch is listed in the provided facts as of 2026-09-29; monitor Mozilla advisories and apply updates when published.
Does CVE-2026-84135 require authentication?
No; exploitation does not require authentication or user interaction according to the provided vulnerability data.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84135
- cve.org/CVERecord?id=CVE-2026-84135
- bugzilla.mozilla.org/show_bug.cgi?id=2046661
- mozilla.org/security/advisories/mfsa2026-82
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026