CVE-2026-84142: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Affected products

  • Mozilla Firefox: before 155.0.0 (fixed in 155.0.0)
  • Mozilla Thunderbird: before 155.0 (fixed in 155.0)

Published 2026-09-01. Last modified 2026-09-03.