CVE-2026-84120
published 2026-09-01CVE-2026-84120: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2…
PriorityP426medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.22%
12.4th percentile
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 155 | Firefox 155 |
| mozilla | firefox | < 115.40.0 | 115.40.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 116.0 < 140.15.0 | 140.15.0 |
| mozilla | firefox | >= 141.0.0 < 153.2.0 | 153.2.0 |
| mozilla | firefox | >= 154.0.0 < 155.0.0 | 155.0.0 |
| mozilla | firefox_esr | < Firefox ESR 153.2 | Firefox ESR 153.2 |
| mozilla | firefox_esr | < Firefox ESR 115.40 | Firefox ESR 115.40 |
| mozilla | firefox_esr | < Firefox ESR 140.15 | Firefox ESR 140.15 |
| mozilla | thunderbird | < Thunderbird 153.2 | Thunderbird 153.2 |
| mozilla | thunderbird | < Thunderbird 155 | Thunderbird 155 |
| mozilla | thunderbird | < Thunderbird 140.15 | Thunderbird 140.15 |
| mozilla | thunderbird | < 140.15.0 | 140.15.0 |
| mozilla | thunderbird | >= 141.0 < 153.2.0 | 153.2.0 |
| mozilla | thunderbird | >= 154.0 < 155.0 | 155.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: firefox-esr: Firefox: Arbitrary code execution via use-after-free in Audio/Video component
vendor_redhat·2026-09-01·CVSS 5.4
CVE-2026-84120 [MEDIUM] CWE-825 firefox: firefox-esr: Firefox: Arbitrary code execution via use-after-free in Audio/Video component
firefox: firefox-esr: Firefox: Arbitrary code execution via use-after-free in Audio/Video component
A flaw was found in the Audio/Video component of Firefox and Firefox ESR. This use-after-free vulnerability could allow a remote attacker to achieve arbitrary code execution. A use-after-free occurs when a program attempts to use memory that has been deallocated, which can lead to memory corruption and unexpected program behavior. This could enable an attacker to take control of the affected system.
Package: firefox (Red Hat Enterprise Linux 10) - Affected
Package: firefox (Red Hat Enterprise Linux 7) - Affected
Package: firefox (Red Hat Enterprise Linux 8) - Affected
Package: firefox (Red Hat Enterprise Linux 9) - Affected
Mozilla
Mozilla Foundation Security Advisory 2026-88: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-88: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-88
CVE: CVE-2026-84120
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153.2
Mozilla
Mozilla Foundation Security Advisory 2026-86: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-86: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-86
CVE: CVE-2026-84120
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 155
Mozilla
Mozilla Foundation Security Advisory 2026-87: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-87: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-87
CVE: CVE-2026-84120
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.15
Mozilla
Mozilla Foundation Security Advisory 2026-85: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84120
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
Mozilla
Mozilla Foundation Security Advisory 2026-83: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-83: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-83
CVE: CVE-2026-84120
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.40
Mozilla
Mozilla Foundation Security Advisory 2026-82: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-82: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-82
CVE: CVE-2026-84120
Product: Firefox
Impact: high
Fixed in: Firefox 155
Mozilla
Mozilla Foundation Security Advisory 2026-84: CVE-2026-84120
vendor_mozilla·CVSS 5.4
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-84: CVE-2026-84120
Mozilla Foundation Security Advisory 2026-84
CVE: CVE-2026-84120
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.15
GHSA
Use-after-free in the Audio/Video component.
ghsa_unreviewed·2026-09-01
CVE-2026-84120 [MEDIUM] CWE-416 Use-after-free in the Audio/Video component.
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
Bugzilla
CVE-2026-84120 firefox: firefox-esr: Firefox: Arbitrary code execution via use-after-free in Audio/Video component
bugzilla·2026-09-01·CVSS 5.4
CVE-2026-84120 [MEDIUM] CVE-2026-84120 firefox: firefox-esr: Firefox: Arbitrary code execution via use-after-free in Audio/Video component
CVE-2026-84120 firefox: firefox-esr: Firefox: Arbitrary code execution via use-after-free in Audio/Video component
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
https://bugzilla.mozilla.org/show_bug.cgi?id=2058911https://www.mozilla.org/security/advisories/mfsa2026-82/https://www.mozilla.org/security/advisories/mfsa2026-83/https://www.mozilla.org/security/advisories/mfsa2026-84/https://www.mozilla.org/security/advisories/mfsa2026-85/https://www.mozilla.org/security/advisories/mfsa2026-86/https://www.mozilla.org/security/advisories/mfsa2026-87/https://www.mozilla.org/security/advisories/mfsa2026-88/
2026-09-01
Published