Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

These bugs were discovered inside Firefox 154 and various ESR releases, where they caused memory corruption or similar security‑relevant defects. The description indicates that, with sufficient effort, these defects could be exploited to gain unintended privileges or execute arbitrary code. The nature of the bugs suggests an out‑of‑bounds memory write or overflow that could be triggered by crafted content or data.

Affected Systems

The affected builds are Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. All of these are upstream or ESR releases that were superseded by newer security‑patched versions: Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15 and Firefox ESR 153.2.

Risk and Exploitability

A CVSS score is not available, and EPSS data is missing, but the presence of potential memory corruption raises the risk level to high. No listing in CISA KEV yet, but the severity of the underlying bug type implies that the vulnerability is exploitable if an attacker can craft input that triggers the memory corruption. The likely attack vector is local or remote web page content processing, though the exact path is not detailed in the provided data.

Generated by OpenCVE AI on September 1, 2026 at 13:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or the corresponding ESR releases (115.40, 140.15, or 153.2) to apply the fix
  • Apply the security patches detailed in the Mozilla security advisories MFSA2026‑82 through MFSA2026‑85 as published by Mozilla
  • Monitor for any exploitation attempts or related incident reports following the deployment of the updates

Generated by OpenCVE AI on September 1, 2026 at 13:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T15:04:49.615Z

Reserved: 2026-09-01T07:26:02.411Z

Link: CVE-2026-84145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:08.673

Modified: 2026-09-01T15:17:43.323

Link: CVE-2026-84145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer