
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84121 is a sandbox escape vulnerability caused by a use-after-free (UAF) flaw in Firefox's DOM: Security component. Discovered and reported by researcher Yaqoub Aldurayhim, it was publicly disclosed on September 1, 2026, alongside Mozilla's batch security advisories. The vulnerability affects Mozilla Firefox prior to version 155, Firefox ESR prior to 115.40, Firefox ESR prior to 140.15, and Firefox ESR prior to 153.2. It carries a CVSS v3.1 base score of 9.6 (Critical) (Mozilla Advisory, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Firefox's DOM: Security component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Because the flaw resides in a security-sensitive DOM subsystem, successful exploitation can break out of Firefox's content process sandbox, elevating attacker-controlled code to run with broader system privileges. Exploitation requires user interaction — specifically, a victim visiting a malicious web page — but no authentication or special privileges are needed on the attacker's side (Mozilla Advisory, Mozilla ESR 115.40, Mozilla ESR 140.15).
Successful exploitation allows an unauthenticated remote attacker to escape Firefox's content process sandbox and execute arbitrary code outside the sandboxed environment, with the privileges of the browser process. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive data from the host system, modify files, install malware, or cause a denial of service. The changed scope (S:C in the CVSS vector) reflects that the impact extends beyond the browser itself to the underlying operating system (Feedly, Mozilla Advisory).
As of the disclosure date (September 1, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment classifies exploitation as "none" and notes the attack is not automatable, as it requires user interaction (visiting a malicious page). No threat actor attribution has been reported at this time.
Note: No public PoC or detailed technical write-up is currently available; these steps represent the general exploitation pattern for this class of vulnerability (Mozilla Advisory, Feedly).
cmd.exe, /bin/sh, powershell.exe, curl, wget) that are not typical browser subprocesses.Note: No specific IOCs have been publicly documented for this CVE at this time; the above represent general indicators for sandbox escape exploitation of Firefox.
Mozilla has released patched versions addressing CVE-2026-84121: Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Organizations and individual users should update to the appropriate version immediately, prioritizing deployment given the critical sandbox escape severity. No configuration-based workaround has been published; upgrading is the only recommended remediation (Mozilla Advisory, Mozilla ESR 115.40, Mozilla ESR 140.15, Mozilla ESR 153.2).
The vulnerability was disclosed as part of Mozilla's September 1, 2026 batch security advisory, which covered a large number of high-severity issues across Firefox and ESR branches. Security scanning vendors including Tenable published detection plugins (Nessus plugin 342166) shortly after disclosure. Community discussion was observed on Mastodon and aggregator sites such as VulDB and radar.offseq.com, though no notable independent researcher commentary or major media coverage has been identified at this time (Mozilla Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."