
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84124 is a use-after-free vulnerability in the DOM: Core & HTML component of Mozilla Firefox, discovered and reported by security researcher Hyeonjun Ahn. It affects Firefox versions prior to 155, Firefox ESR versions prior to 140.15, and Firefox ESR versions prior to 153.2. Mozilla disclosed and patched the vulnerability on September 1, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium), though Mozilla rates its impact as High (Mozilla Advisory mfsa2026-84, Mozilla Advisory mfsa2026-82).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Firefox's DOM: Core & HTML component (tracked internally as Bug 2061110). Use-after-free flaws arise when a program continues to use a pointer to memory after that memory has been freed, potentially allowing an attacker to control the freed memory region and influence program execution. Exploitation requires user interaction — typically luring a victim to visit a specially crafted web page — and no special privileges are required for the attacker. The attack vector is network-based, making it exploitable remotely (Mozilla Advisory mfsa2026-84, Mozilla Advisory mfsa2026-85).
Successful exploitation of this vulnerability could result in limited confidentiality and integrity impacts, as reflected in the CVSS scoring (low confidentiality impact, low integrity impact, no availability impact). In practice, use-after-free vulnerabilities in browser DOM components can potentially be leveraged for memory corruption, information disclosure, or as a stepping stone toward more severe exploitation such as arbitrary code execution, depending on heap layout and additional primitives available to the attacker. The scope is limited to the affected browser process and does not inherently cross security boundaries on its own (Mozilla Advisory mfsa2026-82, Mozilla Advisory mfsa2026-84).
As of the disclosure date (September 1, 2026), there is no evidence of in-the-wild exploitation of CVE-2026-84124, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable, requiring user interaction. The EPSS score is reported as 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Mozilla Advisory mfsa2026-84, Feedly).
Mozilla has released patches addressing CVE-2026-84124 in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2, all announced on September 1, 2026. Users and administrators should update Firefox to one of these patched versions immediately. No specific configuration-based workarounds have been published; upgrading to a fixed release is the recommended and only confirmed remediation (Mozilla Advisory mfsa2026-82, Mozilla Advisory mfsa2026-84, Mozilla Advisory mfsa2026-85).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."