Thunderbird Mozilla Thunderbird Email client

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mozilla Thunderbird.

Recent Mozilla Thunderbird Security Advisories

Advisory Title Published
mfsa2026-96 Security Vulnerabilities fixed in Thunderbird 153.3 mfsa2026-96 September 16, 2026
mfsa2026-94 Security Vulnerabilities fixed in Thunderbird 156 mfsa2026-94 September 15, 2026
mfsa2026-95 Security Vulnerabilities fixed in Thunderbird 140.16 mfsa2026-95 September 15, 2026
mfsa2026-86 Security Vulnerabilities fixed in Thunderbird 155 mfsa2026-86 September 1, 2026
mfsa2026-88 Security Vulnerabilities fixed in Thunderbird 153.2 mfsa2026-88 September 1, 2026
mfsa2026-87 Security Vulnerabilities fixed in Thunderbird 140.15 mfsa2026-87 September 1, 2026
mfsa2026-78 Security Vulnerabilities fixed in Thunderbird 154 mfsa2026-78 August 18, 2026
mfsa2026-80 Security Vulnerabilities fixed in Thunderbird 153.1 mfsa2026-80 August 18, 2026
mfsa2026-79 Security Vulnerabilities fixed in Thunderbird 140.14 mfsa2026-79 August 18, 2026
mfsa2026-72 Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 July 21, 2026

By the Year

In 2026 there have been 473 vulnerabilities in Mozilla Thunderbird with an average score of 8.0 out of ten. Last year, in 2025 Thunderbird had 157 security vulnerabilities published. That is, 316 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.33.




Year Vulnerabilities Average Score
2026 473 7.98
2025 157 7.65
2024 119 7.15
2023 102 7.49
2022 116 7.56
2021 73 7.23
2020 80 7.59
2019 62 8.21
2018 167 8.24

It may take a day or so for new Thunderbird vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Thunderbird Security Vulnerabilities

Thunderbird <140.16 OOB Read in IMAP Parser via * ID Response
CVE-2026-92240 9.1 - Critical - September 15, 2026

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Out-of-bounds Read

OOB buffer read in Thunderbird IMAP parser before 140.16
CVE-2026-92239 8.1 - High - September 15, 2026

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Out-of-bounds Read

Memory Safety Violation via Malformed Mail Header in Thunderbird <140.16
CVE-2026-92238 9.8 - Critical - September 15, 2026

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

HTTP Request Smuggling

Widget: Win32 Mitigation Bypass in Firefox 156 ESR 153.3
CVE-2026-92079 9.1 - Critical - September 15, 2026

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Firefox Denial-of-service in Security component before 156
CVE-2026-92078 6.5 - Medium - September 15, 2026

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Allocation of Resources Without Limits or Throttling

DoS in Firefox SVG component before v156
CVE-2026-92077 6.5 - Medium - September 15, 2026

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Allocation of Resources Without Limits or Throttling

Firefox 156+ Boundary Condition Flaw in Networking Component
CVE-2026-92076 8.8 - High - September 15, 2026

Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Mitigation bypass in Firefox Networking component pre-156/ESR153.3
CVE-2026-92075 9.1 - Critical - September 15, 2026

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Mitigation Bypass in Firefox Popup Blocker (before 156)
CVE-2026-92074 8.8 - High - September 15, 2026

Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Firefox: PrivEsc via Enterprise Policies pre-156/153.3
CVE-2026-92073 8.8 - High - September 15, 2026

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Improper Privilege Management

Firefox SB boundary issue fixed in v156/ESR153.3
CVE-2026-92072 8 - High - September 15, 2026

Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Firefox Sandbox Escape via Widget Boundaries fixed in v156/ESR 153.3
CVE-2026-92071 9.6 - Critical - September 15, 2026

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Firefox Info Disclosure in Networking Comp (before 156/ESR 153.3)
CVE-2026-92070 4.3 - Medium - September 15, 2026

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Information Disclosure

Firefox Navigation Component Spoofing (fixed in 156)
CVE-2026-92069 5.4 - Medium - September 15, 2026

Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

User Interface (UI) Misrepresentation of Critical Information

Site isolation flaw in Firefox Reader Mode (pre156/ESR153.3)
CVE-2026-92068 5.4 - Medium - September 15, 2026

Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Origin Validation Error

Use-after-free in the Widget: Gtk component
CVE-2026-92067 8.8 - High - September 15, 2026

Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Dangling pointer

Sandbox escape in the Profile Backup component
CVE-2026-92066 9.8 - Critical - September 15, 2026

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Protection Mechanism Failure

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92065 8.8 - High - September 15, 2026

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92064 8.8 - High - September 15, 2026

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Denial-of-service in the Audio/Video component
CVE-2026-92063 6.5 - Medium - September 15, 2026

Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Allocation of Resources Without Limits or Throttling

Privilege escalation in the Session Restore component
CVE-2026-92062 8.8 - High - September 15, 2026

Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Improper Privilege Management

Incorrect boundary conditions in the Security: Process Sandboxing component
CVE-2026-92061 9.8 - Critical - September 15, 2026

Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Buffer Overflow

Use-after-free in the Internationalization component
CVE-2026-92060 8.8 - High - September 15, 2026

Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Dangling pointer

Incorrect boundary conditions in the DOM: Editor component
CVE-2026-92059 9.3 - Critical - September 15, 2026

Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Use-after-free in the Graphics component
CVE-2026-92058 8.8 - High - September 15, 2026

Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Dangling pointer

Mitigation bypass in the Enterprise Policies component
CVE-2026-92057 9.1 - Critical - September 15, 2026

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Use-after-free in the Graphics: Text component
CVE-2026-92056 8.8 - High - September 15, 2026

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Dangling pointer

Privilege escalation in the DevTools component
CVE-2026-92055 8.8 - High - September 15, 2026

Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Improper Privilege Management

Privilege escalation in the Memory component
CVE-2026-92054 8.8 - High - September 15, 2026

Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-92053 8.8 - High - September 15, 2026

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Improper Privilege Management

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
CVE-2026-92052 8.8 - High - September 15, 2026

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Use of Uninitialized Variable

Spoofing issue due to invalid pointer in the Graphics component
CVE-2026-92051 9.1 - Critical - September 15, 2026

Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

NULL Pointer Dereference

Sandbox escape due to race condition in the XPConnect component
CVE-2026-92050 9.1 - Critical - September 15, 2026

Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Race Condition

Use-after-free in the Widget: Win32 component
CVE-2026-92049 8.8 - High - September 15, 2026

Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Dangling pointer

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92048 9 - Critical - September 15, 2026

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Privilege escalation in the Crash Reporting component
CVE-2026-92047 8.8 - High - September 15, 2026

Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Improper Privilege Management

Use-after-free in the Graphics component
CVE-2026-92046 8.8 - High - September 15, 2026

Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Dangling pointer

Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVE-2026-92045 9.6 - Critical - September 15, 2026

Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Buffer Overflow

Information disclosure in the Networking: HTTP component
CVE-2026-92044 7.5 - High - September 15, 2026

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Information Disclosure

Privilege escalation due to incorrect boundary conditions in the Audio/Video component
CVE-2026-92043 8.8 - High - September 15, 2026

Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Classic Buffer Overflow

Race condition in the DOM: Content Processes component
CVE-2026-92042 7.5 - High - September 15, 2026

Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Race Condition

Mitigation bypass in the DOM: Networking component
CVE-2026-92041 9.1 - Critical - September 15, 2026

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Use-after-free in the JavaScript: WebAssembly component
CVE-2026-92040 8.8 - High - September 15, 2026

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Dangling pointer

Mitigation bypass in the DOM: Notifications component
CVE-2026-92039 6.3 - Medium - September 15, 2026

Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Mitigation bypass in the Remote Settings Client component
CVE-2026-92038 9.1 - Critical - September 15, 2026

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Protection Mechanism Failure

Incorrect boundary conditions in the DOM: Animation component
CVE-2026-92037 9.8 - Critical - September 15, 2026

Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Buffer Overflow

Incorrect boundary conditions in the Networking: HTTP component
CVE-2026-92036 9.8 - Critical - September 15, 2026

Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Buffer Overflow

Sandbox escape due to incorrect boundary conditions in the Graphics component
CVE-2026-92035 9.6 - Critical - September 15, 2026

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3, Firefox ESR 115.42, and Firefox ESR 140.17.

Buffer Overflow

Site isolation issue in the Graphics component
CVE-2026-92034 9.1 - Critical - September 15, 2026

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

Origin Validation Error

Sandbox escape due to invalid pointer in the Graphics component
CVE-2026-92032 9.6 - Critical - September 15, 2026

Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Buffer Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mozilla Thunderbird or by Mozilla? Click the Watch button to subscribe.

Mozilla
Vendor

Mozilla Thunderbird
Email client

subscribe