CVE-2026-84134
published 2026-09-01CVE-2026-84134: Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.31%
23.5th percentile
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 155 | Firefox 155 |
| mozilla | firefox | < 153.2.0 | 153.2.0 |
| mozilla | firefox | >= 154.0.0 < 155.0.0 | 155.0.0 |
| mozilla | firefox_esr | < Firefox ESR 153.2 | Firefox ESR 153.2 |
| mozilla | thunderbird | < Thunderbird 153.2 | Thunderbird 153.2 |
| mozilla | thunderbird | < Thunderbird 155 | Thunderbird 155 |
| mozilla | thunderbird | < 153.2.0 | 153.2.0 |
| mozilla | thunderbird | >= 154.0 < 155.0 | 155.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Mozilla
Mozilla Foundation Security Advisory 2026-88: CVE-2026-84134
vendor_mozilla
CVE-2026-84134 Mozilla Foundation Security Advisory 2026-88: CVE-2026-84134
Mozilla Foundation Security Advisory 2026-88
CVE: CVE-2026-84134
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153.2
Mozilla
Mozilla Foundation Security Advisory 2026-86: CVE-2026-84134
vendor_mozilla
CVE-2026-84134 Mozilla Foundation Security Advisory 2026-86: CVE-2026-84134
Mozilla Foundation Security Advisory 2026-86
CVE: CVE-2026-84134
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 155
Mozilla
Mozilla Foundation Security Advisory 2026-82: CVE-2026-84134
vendor_mozilla
CVE-2026-84134 Mozilla Foundation Security Advisory 2026-82: CVE-2026-84134
Mozilla Foundation Security Advisory 2026-82
CVE: CVE-2026-84134
Product: Firefox
Impact: high
Fixed in: Firefox 155
Mozilla
Mozilla Foundation Security Advisory 2026-85: CVE-2026-84134
vendor_mozilla
CVE-2026-84134 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84134
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84134
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
VulDB
Mozilla Firefox up to 153.1/154 Profile Backup Remote Code Execution (Nessus ID 342318)
vuldb·2026-09-03
CVE-2026-84134 [CRITICAL] Mozilla Firefox up to 153.1/154 Profile Backup Remote Code Execution (Nessus ID 342318)
A vulnerability labeled as critical has been found in Mozilla Firefox up to 153.1/154. This issue affects some unknown processing of the component Profile Backup. Such manipulation leads to Remote Code Execution.
This vulnerability is referenced as CVE-2026-84134. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
GHSA
Other issue in the Profile Backup component.
ghsa_unreviewed·2026-09-01
CVE-2026-84134 Other issue in the Profile Backup component.
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-01
Published