CVE-2026-84143: pre-auth remote code execution in Mozilla Firefox

An unauthenticated remote attacker can execute arbitrary code against Mozilla Firefox by exploiting a memory-corruption bug (CVE-2026-84143). The weakness is classified under CWE-119 and the CVSS vector indicates network access with no privilege or user interaction required. Public data does not list specific affected releases in the supplied affected list; third-party reporting indicates the issue was addressed in later product builds. Patch availability is not indicated in the provided facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00378
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high urgency because the flaw allows unauthenticated remote code execution over the network with no user interaction required, and memory-corruption issues are frequently exploitable.

What is CVE-2026-84143?

An unauthenticated remote attacker can execute arbitrary code against Mozilla Firefox by exploiting a memory-corruption bug (CVE-2026-84143). The weakness is classified under CWE-119 and the CVSS vector indicates network access with no privilege or user interaction required. Public data does not list specific affected releases in the supplied affected list; third-party reporting indicates the issue was addressed in later product builds. Patch availability is not indicated in the provided facts.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-84143 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-84143

  1. Isolate and restrict network exposure of Firefox installations, especially on internet-facing hosts.
  2. Apply vendor guidance as soon as vendor patches or updates are confirmed available.
  3. Monitor endpoint and network logs for signs of memory-corruption crashes and unusual remote connections targeting Firefox.
  4. Block or limit untrusted content sources and use network-level controls (proxy, filtering) to reduce attack surface.

Frequently asked questions

Is CVE-2026-84143 being actively exploited?

There are no public reports of active exploitation of CVE-2026-84143 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-84143?

The provided facts do not list specific affected versions; third-party reporting indicates the defect existed in older builds and was addressed in later releases, but an authoritative affected-versions list was not supplied.

Is there a patch for CVE-2026-84143?

Patch availability is not indicated in the supplied facts, so follow Mozilla advisories and apply updates from the vendor when they are published.

Does CVE-2026-84143 require authentication?

No — the CVSS vector indicates no privileges or user interaction are required, so an attacker can reach the vulnerability remotely without authentication.

References