CVE-2026-84142: pre-auth remote code execution in Mozilla Firefox

Remote attackers can execute arbitrary code in Mozilla Firefox due to a memory-corruption flaw (CVE-2026-84142). The specific Firefox versions affected are not listed in the provided data. Exploitation requires network access and needs no authentication or user interaction, meaning an attacker can trigger the flaw remotely without a logged-in user or a click.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00561
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a remotely triggerable, no-authentication memory-corruption bug (CVSS 9.8) that can lead to full compromise; prioritize reducing exposure and applying vendor updates as soon as they are released.

What is CVE-2026-84142?

Remote attackers can execute arbitrary code in Mozilla Firefox due to a memory-corruption flaw (CVE-2026-84142). The specific Firefox versions affected are not listed in the provided data. Exploitation requires network access and needs no authentication or user interaction, meaning an attacker can trigger the flaw remotely without a logged-in user or a click.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-84142 being exploited?

There are no public reports of exploitation as of 2026-09-29, and this issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

How to fix CVE-2026-84142

  1. Restrict Firefox exposure from untrusted networks (block access or use network-level filtering).
  2. Enable and enforce browser sandboxing and process isolation features where available.
  3. Monitor endpoints for unusual crashes or suspicious activity and collect crash reports for investigation.
  4. Apply Mozilla's security updates or vendor guidance immediately once a patch is released.

Frequently asked questions

Is CVE-2026-84142 being actively exploited?

No public reports of active exploitation were available as of 2026-09-29, and it is not listed in CISA's Known Exploited Vulnerabilities catalog.

Which Firefox versions are affected by CVE-2026-84142?

The provided data does not list specific affected Firefox versions, so the exact impacted releases are unknown from these facts.

Is there a patch for CVE-2026-84142?

No patch was indicated in the provided data as of 2026-09-29; follow Mozilla's advisories and apply updates when they become available.

Does CVE-2026-84142 require authentication?

No; the vulnerability can be triggered without authentication or user interaction, allowing remote attack without a logged-in user.

References