CVE-2026-84134
Mozilla · Firefox, Thunderbird
A critical flaw exists in the Profile Backup component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.
Executive summary
A critical vulnerability in the Mozilla Profile Backup component enables unauthenticated attackers to achieve full system compromise, necessitating immediate updates.
Vulnerability
This vulnerability resides in the Profile Backup component and is classified as unauthenticated, meaning no user interaction or privilege is required for an attacker to trigger the flaw. The vulnerability allows for full confidentiality, integrity, and availability impact through network exploitation.
Business impact
The CVSS score of 9.8 reflects the critical nature of this flaw, as it allows for remote code execution without authentication. Successful exploitation could lead to total system compromise, resulting in significant data theft, unauthorized persistent access, and potential lateral movement within the network. This poses a severe risk to organizational security and operational continuity.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 155 or later, or to ESR version 153.2 or later, to fully mitigate the vulnerability.
Proactive Monitoring: Monitor network traffic for anomalous patterns originating from the Profile Backup service and review system access logs for unauthorized execution attempts.
Compensating Controls: While no direct virtual patch exists, organizations should restrict network access to the affected applications and enforce strict endpoint security policies to minimize the potential impact of an exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity score of 9.8 and the potential for unauthenticated remote code execution, this vulnerability represents an urgent threat. Security teams must prioritize the deployment of the provided updates across all affected Firefox and Thunderbird installations immediately to prevent potential exploitation.
More Mozilla CVEs all →
Sources
Originally found and disclosed by 5up3rh3i, per the CVE Program record.