Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-84129: Firefox navigation can let sites bypass page isolation

CVE-2026-84129 · published 2 days ago
Summary

A part of Firefox that separates different websites from each other could be tricked, allowing a malicious site to see or affect data from another site. This could lead to privacy or data leakage. Updating Firefox to version 155 (or ESR 153.2) resolves the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mozilla firefox All versions
mozilla thunderbird All versions
Original advisory text
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-346Origin Validation Error
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-84129 · MITRE
Monitor software like this
Free during beta