DIRAS TAKE
Treat this as high urgency because the flaw allows unauthenticated remote code execution over the network with no user interaction required, and memory-corruption issues are frequently exploitable.
What is CVE-2026-84143?
An unauthenticated remote attacker can execute arbitrary code against Mozilla Firefox by exploiting a memory-corruption bug (CVE-2026-84143). The weakness is classified under CWE-119 and the CVSS vector indicates network access with no privilege or user interaction required. Public data does not list specific affected releases in the supplied affected list; third-party reporting indicates the issue was addressed in later product builds. Patch availability is not indicated in the provided facts.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-84143 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-84143
- Isolate and restrict network exposure of Firefox installations, especially on internet-facing hosts.
- Apply vendor guidance as soon as vendor patches or updates are confirmed available.
- Monitor endpoint and network logs for signs of memory-corruption crashes and unusual remote connections targeting Firefox.
- Block or limit untrusted content sources and use network-level controls (proxy, filtering) to reduce attack surface.
Frequently asked questions
Is CVE-2026-84143 being actively exploited?
There are no public reports of active exploitation of CVE-2026-84143 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-84143?
The provided facts do not list specific affected versions; third-party reporting indicates the defect existed in older builds and was addressed in later releases, but an authoritative affected-versions list was not supplied.
Is there a patch for CVE-2026-84143?
Patch availability is not indicated in the supplied facts, so follow Mozilla advisories and apply updates from the vendor when they are published.
Does CVE-2026-84143 require authentication?
No — the CVSS vector indicates no privileges or user interaction are required, so an attacker can reach the vulnerability remotely without authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84143
- cve.org/CVERecord?id=CVE-2026-84143
- bugzilla.mozilla.org/buglist.cgi?bug_id=2048793%2C2054645%2C2057114%2C2059109%2C2061287
- bugzilla.mozilla.org/buglist.cgi?bug_id=2054631%2C2054657%2C2055007%2C2055681%2C2057107%2C2058087%2C2058088%2C2058090%2C2058095%2C2058101%2C2059183%2C2059185%2C2061301%2C2061325
- bugzilla.mozilla.org/show_bug.cgi?id=2057108
- mozilla.org/security/advisories/mfsa2026-82
- mozilla.org/security/advisories/mfsa2026-84
- mozilla.org/security/advisories/mfsa2026-85
- mozilla.org/security/advisories/mfsa2026-86
- mozilla.org/security/advisories/mfsa2026-87
- mozilla.org/security/advisories/mfsa2026-88
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026