ZeroHour

CVE-2026-84132

mass

Information Disclosure in Mozilla Firefox and Thunderbird HTTP Networking

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-84132 is an information-disclosure vulnerability (CWE-200) in the Networking: HTTP component of Mozilla Firefox and Mozilla Thunderbird. Because the flaw sits in the HTTP networking stack, it is triggered remotely through the client's handling of network traffic, and its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) indicates it is exploitable over a network with low attack complexity and without privileges or user interaction. A successful attacker gains access to sensitive information processed by the affected client (high confidentiality impact), with no impact on integrity or availability. Users running Firefox before 155, Firefox ESR before 153.2, Thunderbird before 155, or Thunderbird before 153.2 are affected. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS assigns a low 0.3% probability (17th percentile) of exploitation within the next 30 days.

What to do: Upgrade all managed endpoints to Firefox 155 or Firefox ESR 153.2 (or later) and to Thunderbird 155 or Thunderbird 153.2 (or later), and verify installed versions through your device-management or EDR inventory. No specific workaround is documented in the available data, so updating is the primary mitigation; keep automatic updates enabled. Given the confidentiality-only impact and the absence of known exploitation, patching on your standard cadence is reasonable, with priority for users and hosts that handle sensitive information.

Affected
mozilla firefoxbefore 155
mozilla firefox_esrbefore 153.2
mozilla thunderbirdbefore 155
mozilla thunderbirdbefore 153.2 (older 153.x branch)
Estimated exposure
masshundreds of millions of users (Firefox alone is estimated at roughly 200M+ users worldwide, with Thunderbird adding millions more) — Firefox is one of the world's most widely deployed desktop browsers with a publicly estimated user base in the hundreds of millions and Thunderbird has millions of desktop users, and because the fixes land in new major releases…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.