Mozilla Thunderbird Email client
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Mozilla Thunderbird.
Recent Mozilla Thunderbird Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-96 | Security Vulnerabilities fixed in Thunderbird 153.3 mfsa2026-96 | September 16, 2026 |
| mfsa2026-94 | Security Vulnerabilities fixed in Thunderbird 156 mfsa2026-94 | September 15, 2026 |
| mfsa2026-95 | Security Vulnerabilities fixed in Thunderbird 140.16 mfsa2026-95 | September 15, 2026 |
| mfsa2026-86 | Security Vulnerabilities fixed in Thunderbird 155 mfsa2026-86 | September 1, 2026 |
| mfsa2026-88 | Security Vulnerabilities fixed in Thunderbird 153.2 mfsa2026-88 | September 1, 2026 |
| mfsa2026-87 | Security Vulnerabilities fixed in Thunderbird 140.15 mfsa2026-87 | September 1, 2026 |
| mfsa2026-78 | Security Vulnerabilities fixed in Thunderbird 154 mfsa2026-78 | August 18, 2026 |
| mfsa2026-80 | Security Vulnerabilities fixed in Thunderbird 153.1 mfsa2026-80 | August 18, 2026 |
| mfsa2026-79 | Security Vulnerabilities fixed in Thunderbird 140.14 mfsa2026-79 | August 18, 2026 |
| mfsa2026-72 | Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 | July 21, 2026 |
By the Year
In 2026 there have been 473 vulnerabilities in Mozilla Thunderbird with an average score of 8.0 out of ten. Last year, in 2025 Thunderbird had 157 security vulnerabilities published. That is, 316 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.33.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 473 | 7.98 |
| 2025 | 157 | 7.65 |
| 2024 | 119 | 7.15 |
| 2023 | 102 | 7.49 |
| 2022 | 116 | 7.56 |
| 2021 | 73 | 7.23 |
| 2020 | 80 | 7.59 |
| 2019 | 62 | 8.21 |
| 2018 | 167 | 8.24 |
It may take a day or so for new Thunderbird vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Thunderbird Security Vulnerabilities
Thunderbird <140.16 OOB Read in IMAP Parser via * ID Response
CVE-2026-92240
9.1 - Critical
- September 15, 2026
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Out-of-bounds Read
OOB buffer read in Thunderbird IMAP parser before 140.16
CVE-2026-92239
8.1 - High
- September 15, 2026
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Out-of-bounds Read
Memory Safety Violation via Malformed Mail Header in Thunderbird <140.16
CVE-2026-92238
9.8 - Critical
- September 15, 2026
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
HTTP Request Smuggling
Widget: Win32 Mitigation Bypass in Firefox 156 ESR 153.3
CVE-2026-92079
9.1 - Critical
- September 15, 2026
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Firefox Denial-of-service in Security component before 156
CVE-2026-92078
6.5 - Medium
- September 15, 2026
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Allocation of Resources Without Limits or Throttling
DoS in Firefox SVG component before v156
CVE-2026-92077
6.5 - Medium
- September 15, 2026
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Allocation of Resources Without Limits or Throttling
Firefox 156+ Boundary Condition Flaw in Networking Component
CVE-2026-92076
8.8 - High
- September 15, 2026
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Mitigation bypass in Firefox Networking component pre-156/ESR153.3
CVE-2026-92075
9.1 - Critical
- September 15, 2026
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Mitigation Bypass in Firefox Popup Blocker (before 156)
CVE-2026-92074
8.8 - High
- September 15, 2026
Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Firefox: PrivEsc via Enterprise Policies pre-156/153.3
CVE-2026-92073
8.8 - High
- September 15, 2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Firefox SB boundary issue fixed in v156/ESR153.3
CVE-2026-92072
8 - High
- September 15, 2026
Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Firefox Sandbox Escape via Widget Boundaries fixed in v156/ESR 153.3
CVE-2026-92071
9.6 - Critical
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Firefox Info Disclosure in Networking Comp (before 156/ESR 153.3)
CVE-2026-92070
4.3 - Medium
- September 15, 2026
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Information Disclosure
Firefox Navigation Component Spoofing (fixed in 156)
CVE-2026-92069
5.4 - Medium
- September 15, 2026
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
User Interface (UI) Misrepresentation of Critical Information
Site isolation flaw in Firefox Reader Mode (pre156/ESR153.3)
CVE-2026-92068
5.4 - Medium
- September 15, 2026
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Origin Validation Error
Use-after-free in the Widget: Gtk component
CVE-2026-92067
8.8 - High
- September 15, 2026
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Dangling pointer
Sandbox escape in the Profile Backup component
CVE-2026-92066
9.8 - Critical
- September 15, 2026
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Protection Mechanism Failure
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92065
8.8 - High
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92064
8.8 - High
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Denial-of-service in the Audio/Video component
CVE-2026-92063
6.5 - Medium
- September 15, 2026
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Allocation of Resources Without Limits or Throttling
Privilege escalation in the Session Restore component
CVE-2026-92062
8.8 - High
- September 15, 2026
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Incorrect boundary conditions in the Security: Process Sandboxing component
CVE-2026-92061
9.8 - Critical
- September 15, 2026
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Buffer Overflow
Use-after-free in the Internationalization component
CVE-2026-92060
8.8 - High
- September 15, 2026
Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Dangling pointer
Incorrect boundary conditions in the DOM: Editor component
CVE-2026-92059
9.3 - Critical
- September 15, 2026
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Use-after-free in the Graphics component
CVE-2026-92058
8.8 - High
- September 15, 2026
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Dangling pointer
Mitigation bypass in the Enterprise Policies component
CVE-2026-92057
9.1 - Critical
- September 15, 2026
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Use-after-free in the Graphics: Text component
CVE-2026-92056
8.8 - High
- September 15, 2026
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Dangling pointer
Privilege escalation in the DevTools component
CVE-2026-92055
8.8 - High
- September 15, 2026
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Privilege escalation in the Memory component
CVE-2026-92054
8.8 - High
- September 15, 2026
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-92053
8.8 - High
- September 15, 2026
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
CVE-2026-92052
8.8 - High
- September 15, 2026
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Use of Uninitialized Variable
Spoofing issue due to invalid pointer in the Graphics component
CVE-2026-92051
9.1 - Critical
- September 15, 2026
Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
NULL Pointer Dereference
Sandbox escape due to race condition in the XPConnect component
CVE-2026-92050
9.1 - Critical
- September 15, 2026
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Race Condition
Use-after-free in the Widget: Win32 component
CVE-2026-92049
8.8 - High
- September 15, 2026
Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Dangling pointer
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92048
9 - Critical
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Privilege escalation in the Crash Reporting component
CVE-2026-92047
8.8 - High
- September 15, 2026
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Improper Privilege Management
Use-after-free in the Graphics component
CVE-2026-92046
8.8 - High
- September 15, 2026
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Dangling pointer
Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVE-2026-92045
9.6 - Critical
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Buffer Overflow
Information disclosure in the Networking: HTTP component
CVE-2026-92044
7.5 - High
- September 15, 2026
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Information Disclosure
Privilege escalation due to incorrect boundary conditions in the Audio/Video component
CVE-2026-92043
8.8 - High
- September 15, 2026
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Classic Buffer Overflow
Race condition in the DOM: Content Processes component
CVE-2026-92042
7.5 - High
- September 15, 2026
Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Race Condition
Mitigation bypass in the DOM: Networking component
CVE-2026-92041
9.1 - Critical
- September 15, 2026
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Use-after-free in the JavaScript: WebAssembly component
CVE-2026-92040
8.8 - High
- September 15, 2026
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Dangling pointer
Mitigation bypass in the DOM: Notifications component
CVE-2026-92039
6.3 - Medium
- September 15, 2026
Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Mitigation bypass in the Remote Settings Client component
CVE-2026-92038
9.1 - Critical
- September 15, 2026
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Protection Mechanism Failure
Incorrect boundary conditions in the DOM: Animation component
CVE-2026-92037
9.8 - Critical
- September 15, 2026
Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Buffer Overflow
Incorrect boundary conditions in the Networking: HTTP component
CVE-2026-92036
9.8 - Critical
- September 15, 2026
Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Buffer Overflow
Sandbox escape due to incorrect boundary conditions in the Graphics component
CVE-2026-92035
9.6 - Critical
- September 15, 2026
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3, Firefox ESR 115.42, and Firefox ESR 140.17.
Buffer Overflow
Site isolation issue in the Graphics component
CVE-2026-92034
9.1 - Critical
- September 15, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Origin Validation Error
Sandbox escape due to invalid pointer in the Graphics component
CVE-2026-92032
9.6 - Critical
- September 15, 2026
Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Mozilla Thunderbird or by Mozilla? Click the Watch button to subscribe.