CVE-2026-84135: pre-auth remote code execution in Mozilla Firefox

Remote attackers can execute arbitrary code in Mozilla Firefox due to an input validation vulnerability (CVE-2026-84135). The flaw requires only network access and does not require authentication or user interaction, enabling exploitation across exposed Firefox instances. The vulnerability is mapped to CWE-20 and carries a CVSS 3.1 score of 9.8, indicating complete confidentiality, integrity, and availability impact if exploited. Vendor guidance and specific affected-version details are not present in the provided facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00449
CWE
CWE-20
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a critical, pre-auth remote code execution with no patch listed in the facts; immediately reduce exposure for internet-facing Firefox installs and prepare to apply vendor updates as soon as they are published.

What is CVE-2026-84135?

Remote attackers can execute arbitrary code in Mozilla Firefox due to an input validation vulnerability (CVE-2026-84135). The flaw requires only network access and does not require authentication or user interaction, enabling exploitation across exposed Firefox instances. The vulnerability is mapped to CWE-20 and carries a CVSS 3.1 score of 9.8, indicating complete confidentiality, integrity, and availability impact if exploited. Vendor guidance and specific affected-version details are not present in the provided facts.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-84135 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-84135

  1. Restrict network exposure of Firefox endpoints and block access to untrusted sites at network edge.
  2. Enable automatic updates for Firefox and apply the vendor's security updates immediately when released.
  3. Harden host configurations: use sandboxing, least-privilege policies, and endpoint isolation for users running Firefox.
  4. Monitor logs and intrusion-detection alerts for anomalous browser activity and indicators of compromise related to remote code execution.

Frequently asked questions

Is CVE-2026-84135 being actively exploited?

There are no public reports of active exploitation of CVE-2026-84135 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-84135?

The provided facts do not list specific affected Firefox versions or a vendor-supplied affected-versions range.

Is there a patch for CVE-2026-84135?

No patch is listed in the provided facts as of 2026-09-29; monitor Mozilla advisories and apply updates when published.

Does CVE-2026-84135 require authentication?

No; exploitation does not require authentication or user interaction according to the provided vulnerability data.

References