SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-84133

CRITICAL · CVSS 9.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A site isolation vulnerability in the Push Subscriptions component of Firefox could potentially allow malicious websites to access sensitive data from other sites. Users and organizations relying on Firefox for secure browsing should prioritize updating to Firefox version 155 or Firefox ESR 153.2 to mitigate the risk of data exposure.

CVE
CVE-2026-84133
Severity
CRITICAL
CVSS
9.8
EPSS
0.18%
Firefox

Original NVD Description

Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)