CVE-2026-84124

Published Sep 1, 2026

Last updated 16 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-84124 is a use-after-free vulnerability found within the DOM: Core & HTML component. This flaw was addressed by Mozilla in several product updates. Specifically, the vulnerability was patched in Firefox version 155, Firefox ESR versions 140.15 and 153.2, and corresponding Thunderbird versions 140.15, 153.2, and 155.

Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Source
security@mozilla.org
NVD status
Analyzed
Products
firefox, thunderbird

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.4
Impact score
2.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

8

Configurations