EXPOSURES › CVE-2026-84140
CVE-2026-84140
CRITICALMozilla Firefox had a critical site isolation DOM navigation vulnerability fixed in Firefox 155 and ESR 153.2.
A critical site isolation issue in Firefox's DOM navigation component allowed potential cross-site scripting or data leakage, fixed in Firefox 155 and ESR 153.2. DIB orgs must ensure ESR updates are applied promptly, as unpatched browsers are high-value targets for ransomware and data exfiltration. This is not an RCE or zero-day; it was responsibly disclosed and patched.
Shame score — Critical CVSS 9.8 site isolation flaw in a widely deployed browser, though patched promptly, still represents a significant exposure if left unpatched.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.