Junglewise Threat Intelligence

CVE-2026-84134: Mozilla Firefox other issue in Profile Backup component

CVE-2026-84134 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird's Profile Backup component contained a security issue that could potentially be exploited to affect browser functionality or security. The vulnerability has been patched in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Technical details

CVE-2026-84134 is classified as an "other issue" in the Profile Backup component of Firefox and Thunderbird. Limited technical details are available from the referenced advisory, but the vulnerability exists in code responsible for backing up user profile data. The nature of the issue is not fully disclosed in the available documentation. The vulnerability was identified and fixed by Mozilla across multiple product lines and versions. Users running Firefox 155, Firefox ESR 153.2, Thunderbird 155, or Thunderbird 153.2 and later have the fix applied.

Affected products

  • Mozilla Firefox prior to 155
  • Mozilla Firefox ESR prior to 153.2
  • Mozilla Thunderbird prior to 155
  • Mozilla Thunderbird ESR prior to 153.2

Timeline

  • 2026-09-01: disclosed: Vulnerability publicly disclosed via Mozilla Security Advisory MFSA2026-82
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2

References

Related threats