Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-84121 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-09-01 |
| Vendor | Mozilla |
| Product | Firefox |
| CVSS Score | 9.6 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Mozilla fixed two use-after-free vulnerabilities in Firefox DOM components, both leading to a sandbox escape:
| CVE | Component | CVSS |
|---|---|---|
| CVE-2026-84121 | DOM: Security | 9.6 |
| CVE-2026-84119 | DOM: Navigation | 9.6 |
Both were fixed in Firefox 155 and in the extended support releases ESR 115.40, ESR 140.15 and ESR 153.2.
In a browser’s security model, a sandbox escape is the highest-impact vulnerability class. Firefox isolates page content processing in low-privilege child processes; the sandbox is the last boundary between a malicious site and the user’s operating system. Breaking it means that visiting a crafted page - or loading a malicious ad on a trusted site - can lead to code execution outside the isolation boundary.
The browser is also the application that encounters the largest volume of untrusted data on an employee workstation during a working day.
Required Actions
- Update Firefox to version 155 or, in enterprise environments, to the appropriate ESR release: 115.40, 140.15 or 153.2, depending on your branch.
- Verify the actual state of the fleet, not just the update policy configuration. Firefox installed manually or through a system package manager often sits outside the IT-managed update cycle.
- Force a browser restart after updating. Replacing files is not enough - the vulnerable process runs until the session closes, and workstations often go weeks without a reboot.
- Check versions on Linux systems. Distribution repositories ship Firefox packages behind Mozilla’s release; confirm the delivered build contains the fix.
- Update container and VM images where Firefox is used for testing, automation or isolated browsing.
- If you are on ESR 115, plan migration to a newer branch. That release is approaching end of support, and staying on it widens the exposure window for future vulnerabilities.
Who Is Affected?
Every organisation where Firefox runs on workstations or servers - as the primary browser, or as a second, less closely governed client alongside Chrome or Edge.
Firefox ESR is the standard in public administration, universities and parts of the financial sector, chosen for stability and compliance requirements. Those deployments deserve particular attention: commitment to ESR is sometimes mistaken for not needing frequent updates, whereas ESR receives security fixes on the same cadence as the main branch.
Risk is elevated on endpoints with access to critical systems and on administrator workstations, where a sandbox escape translates directly into access to privileged credentials.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
