DIRAS TAKE
Urgent: this is a remotely reachable RCE that requires no authentication, and vendor fixes are recorded for Firefox 155 and ESR 153.2; prioritize reducing exposure and applying vendor updates when available.
What is CVE-2026-84140?
An attacker can cause remote code execution in Firefox via a site isolation bug in the DOM navigation component. CVE-2026-84140 affects Firefox and Thunderbird; vendor notes say the issue was fixed in Firefox 155 and Firefox ESR 153.2 (and corresponding Thunderbird releases). The flaw requires only network access and no user interaction or credentials to exploit.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-84140 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84140
- Follow vendor guidance and apply the vendor's fixes when they are released for your Firefox/Thunderbird builds.
- Restrict network exposure of affected clients by limiting access to untrusted networks and blocking unneeded ports.
- Monitor browser crash reports, unusual process spawning, and outbound connections from endpoints running Firefox or Thunderbird.
- Ensure endpoint telemetry and EDR are collecting sufficient data to investigate suspicious activity and prepare to deploy updates quickly.
Frequently asked questions
Is CVE-2026-84140 being actively exploited?
There are no public reports of exploitation of CVE-2026-84140 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-84140?
Vendor notes indicate the flaw was fixed in Firefox 155 and Firefox ESR 153.2, which implies earlier releases of Firefox and the corresponding Thunderbird builds are affected until those fixes are applied.
Is there a patch for CVE-2026-84140?
Vendor information lists fixes in Firefox 155 and Firefox ESR 153.2 and corresponding Thunderbird releases; apply those vendor-provided updates when available for your installations.
Does CVE-2026-84140 require authentication?
No; the vulnerability can be triggered without authentication or user interaction, requiring only network access to the affected Firefox or Thunderbird client.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84140
- cve.org/CVERecord?id=CVE-2026-84140
- bugzilla.mozilla.org/show_bug.cgi?id=2063780
- mozilla.org/security/advisories/mfsa2026-82
- mozilla.org/security/advisories/mfsa2026-85
- mozilla.org/security/advisories/mfsa2026-86
- mozilla.org/security/advisories/mfsa2026-88
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026