Mozilla Thunderbird Email client
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Mozilla Thunderbird.
Recent Mozilla Thunderbird Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-78 | Security Vulnerabilities fixed in Thunderbird 154 mfsa2026-78 | August 18, 2026 |
| mfsa2026-80 | Security Vulnerabilities fixed in Thunderbird 153.1 mfsa2026-80 | August 18, 2026 |
| mfsa2026-79 | Security Vulnerabilities fixed in Thunderbird 140.14 mfsa2026-79 | August 18, 2026 |
| mfsa2026-72 | Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 | July 21, 2026 |
| mfsa2026-71 | Security Vulnerabilities fixed in Thunderbird 153 mfsa2026-71 | July 21, 2026 |
| mfsa2026-64 | Security Vulnerabilities fixed in Thunderbird 140.12.1 mfsa2026-64 | June 30, 2026 |
| mfsa2026-63 | Security Vulnerabilities fixed in Thunderbird 152.0.1 mfsa2026-63 | June 30, 2026 |
| mfsa2026-61 | Security Vulnerabilities fixed in Thunderbird 140.12 mfsa2026-61 | June 16, 2026 |
| mfsa2026-60 | Security Vulnerabilities fixed in Thunderbird 152 mfsa2026-60 | June 16, 2026 |
| mfsa2026-51 | Security Vulnerabilities fixed in Thunderbird 140.11 mfsa2026-51 | May 19, 2026 |
By the Year
In 2026 there have been 365 vulnerabilities in Mozilla Thunderbird with an average score of 7.8 out of ten. Last year, in 2025 Thunderbird had 157 security vulnerabilities published. That is, 208 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.18.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 365 | 7.83 |
| 2025 | 157 | 7.65 |
| 2024 | 119 | 7.15 |
| 2023 | 102 | 7.49 |
| 2022 | 116 | 7.56 |
| 2021 | 73 | 7.23 |
| 2020 | 80 | 7.59 |
| 2019 | 62 | 8.21 |
| 2018 | 167 | 8.24 |
It may take a day or so for new Thunderbird vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Thunderbird Security Vulnerabilities
Memory corruption bugs in Firefox 153
CVE-2026-74989
9.8 - Critical
- August 18, 2026
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Buffer Overflow
Firefox ESR 153.0 Memory Corruption Vulnerability (fixed in 153.1)
CVE-2026-74988
9.8 - Critical
- August 18, 2026
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Buffer Overflow
CSS Parsing Component Site Isolation Flaw Fixed in Firefox 154 & ESR 153.1
CVE-2026-74986
9.1 - Critical
- August 18, 2026
Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Information Disclosure
Firefox 154 ESR 153.1 Fixed PrivEsc in Enterprise Policies
CVE-2026-74985
9.8 - Critical
- August 18, 2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Race Condition in JS Engine, Firefox <154, fixed v154
CVE-2026-74984
6.8 - Medium
- August 18, 2026
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Race Condition
DoS in Firefox Widget component before 154/ESR153.1
CVE-2026-74982
7.5 - High
- August 18, 2026
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Resource Exhaustion
Site isolation issue in the Audio/Video: Web Codecs component
CVE-2026-74981
8.1 - High
- August 18, 2026
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Mitigation bypass in the Add-ons Manager component
CVE-2026-74979
9.8 - Critical
- August 18, 2026
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Authorization
Clickjacking issue in the Widget component
CVE-2026-74978
8.1 - High
- August 18, 2026
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Clickjacking
Integer overflow in the Graphics component
CVE-2026-74977
7.5 - High
- August 18, 2026
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Integer Overflow or Wraparound
Site isolation issue in the Graphics component
CVE-2026-74970
5.4 - Medium
- August 18, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Site isolation issue in the Graphics: WebRender component
CVE-2026-74968
5.4 - Medium
- August 18, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Same-origin policy bypass in the DOM: Service Workers component
CVE-2026-74956
9.1 - Critical
- August 18, 2026
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Object Type Confusion
Information disclosure in the WebRTC component
CVE-2026-74958
7.5 - High
- August 18, 2026
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Clickjacking
Side-channel in the Web Audio component
CVE-2026-74961
9.1 - Critical
- August 18, 2026
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Side Channel Attack
Information disclosure in the Form Autofill component
CVE-2026-74966
7.5 - High
- August 18, 2026
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Privacy violation
Privilege escalation in the Application Update component
CVE-2026-74952
8.8 - High
- August 18, 2026
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Improper Privilege Management
Information disclosure due to side-channel in the Storage: Cache API component
CVE-2026-74954
7.5 - High
- August 18, 2026
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Side Channel Attack
Privilege escalation in the Request Handling component
CVE-2026-74955
8.8 - High
- August 18, 2026
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Use-after-free in the JavaScript: GC component
CVE-2026-74937
8.8 - High
- August 18, 2026
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Dangling pointer
Mitigation bypass in the JavaScript: GC component
CVE-2026-74938
9.1 - Critical
- August 18, 2026
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Protection Mechanism Failure
Privilege escalation due to invalid pointer in the Graphics component
CVE-2026-74947
8.8 - High
- August 18, 2026
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Release of Invalid Pointer or Reference
Privilege escalation in the Downloads API component
CVE-2026-74950
8.8 - High
- August 18, 2026
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Sandbox escape in the Remote Settings Client component
CVE-2026-75874
10 - Critical
- August 18, 2026
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Protection Mechanism Failure
Mitigation bypass in the Data Loss Prevention component
CVE-2026-74983
8.1 - High
- August 18, 2026
Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Protection Mechanism Failure
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153
CVE-2026-74987
9.8 - Critical
- August 18, 2026
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Buffer Overflow
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153
CVE-2026-74990
9.8 - Critical
- August 18, 2026
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Buffer Overflow
Information disclosure in the DOM: Push Subscriptions component
CVE-2026-74972
4.3 - Medium
- August 18, 2026
Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information Disclosure
Race condition, use-after-free in the Graphics component
CVE-2026-74973
4.2 - Medium
- August 18, 2026
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Race Condition
Same-origin policy bypass in the Graphics: ImageLib component
CVE-2026-74974
5.4 - Medium
- August 18, 2026
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-74976
6.5 - Medium
- August 18, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Object Type Confusion
Privilege escalation in the Shell Integration component
CVE-2026-74965
8.8 - High
- August 18, 2026
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Improper Privilege Management
Use-after-free in the Layout: Text and Fonts component
CVE-2026-74969
8.8 - High
- August 18, 2026
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Dangling pointer
Information disclosure in the DOM: UI Events & Focus Handling component
CVE-2026-74971
4.3 - Medium
- August 18, 2026
Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information Disclosure
Same-origin policy bypass in the Audio/Video: Playback component
CVE-2026-74967
5.4 - Medium
- August 18, 2026
Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Integer overflow in the Graphics component
CVE-2026-74964
9.8 - Critical
- August 18, 2026
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Integer Overflow or Wraparound
Same-origin policy bypass in the Networking: Cookies component
CVE-2026-74963
5.4 - Medium
- August 18, 2026
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Site isolation issue in the Networking: Cookies component
CVE-2026-74962
8.1 - High
- August 18, 2026
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Site isolation issue in the WebExtensions component
CVE-2026-74960
- August 18, 2026
Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Mitigation bypass in the Storage: Cache API component
CVE-2026-74959
- August 18, 2026
Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Mitigation bypass in the Safe Browsing component
CVE-2026-74957
- August 18, 2026
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Privilege escalation in the Networking: Cookies component
CVE-2026-74953
8.8 - High
- August 18, 2026
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Improper Privilege Management
Privilege escalation due to use-after-free in the Graphics: Canvas2D component
CVE-2026-74949
8.8 - High
- August 18, 2026
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Dangling pointer
Use-after-free in the DOM: Core & HTML component
CVE-2026-74944
- August 18, 2026
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information disclosure in the Graphics: Text component
CVE-2026-74945
- August 18, 2026
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information disclosure in the Graphics component
CVE-2026-74948
- August 18, 2026
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-74946
8.8 - High
- August 18, 2026
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Buffer Overflow
Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-74941
8.8 - High
- August 18, 2026
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Improper Privilege Management
Privilege escalation in the Remote Settings Client component
CVE-2026-74942
8.8 - High
- August 18, 2026
Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Improper Privilege Management
Use-after-free in the Graphics: ImageLib component
CVE-2026-74943
- August 18, 2026
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Mozilla Thunderbird or by Mozilla? Click the Watch button to subscribe.