Thunderbird Mozilla Thunderbird Email client

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mozilla Thunderbird.

Recent Mozilla Thunderbird Security Advisories

Advisory Title Published
mfsa2026-72 Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 July 21, 2026
mfsa2026-71 Security Vulnerabilities fixed in Thunderbird 153 mfsa2026-71 July 21, 2026
mfsa2026-64 Security Vulnerabilities fixed in Thunderbird 140.12.1 mfsa2026-64 June 30, 2026
mfsa2026-63 Security Vulnerabilities fixed in Thunderbird 152.0.1 mfsa2026-63 June 30, 2026
mfsa2026-61 Security Vulnerabilities fixed in Thunderbird 140.12 mfsa2026-61 June 16, 2026
mfsa2026-60 Security Vulnerabilities fixed in Thunderbird 152 mfsa2026-60 June 16, 2026
mfsa2026-51 Security Vulnerabilities fixed in Thunderbird 140.11 mfsa2026-51 May 19, 2026
mfsa2026-50 Security Vulnerabilities fixed in Thunderbird 151 mfsa2026-50 May 19, 2026
mfsa2026-43 Security Vulnerabilities fixed in Thunderbird 150.0.2 mfsa2026-43 May 8, 2026
mfsa2026-44 Security Vulnerabilities fixed in Thunderbird 140.10.2 mfsa2026-44 May 8, 2026

By the Year

In 2026 there have been 310 vulnerabilities in Mozilla Thunderbird with an average score of 7.8 out of ten. Last year, in 2025 Thunderbird had 157 security vulnerabilities published. That is, 153 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.15.




Year Vulnerabilities Average Score
2026 310 7.81
2025 157 7.65
2024 119 7.15
2023 102 7.49
2022 116 7.56
2021 73 7.23
2020 80 7.59
2019 62 8.21
2018 167 8.24

It may take a day or so for new Thunderbird vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Thunderbird Security Vulnerabilities

Thunderbird MIME header OBO read before 153
CVE-2026-14899 7.5 - High - July 22, 2026

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.

off-by-five

Firefox ESR Memory Safety Bug (ESR 115.37/140.12) Fixed in 115.38/140.13
CVE-2026-16361 9.8 - Critical - July 21, 2026

Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.

Buffer Overflow

Memory Safety Bugs in Firefox 115.37-140.12 & 152 (fixed 153 ESR)
CVE-2026-16360 9.8 - Critical - July 21, 2026

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Buffer Overflow

Memory Safety Bugs in Firefox 152 & ESR 140.12 (fixed 153/140.13)
CVE-2026-16412 9.8 - Critical - July 21, 2026

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Buffer Overflow

Firefox 152 Memory Safety Bugs Causing Arbitrary Code Exec
CVE-2026-16411 9.8 - Critical - July 21, 2026

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Buffer Overflow

Firefox JIT Miscompilation in JS Engine (CVE-2026-16410)
CVE-2026-16410 9.8 - Critical - July 21, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Object Type Confusion

Firefox 153: Invalid Pointer in PSM Component
CVE-2026-16409 7.5 - High - July 21, 2026

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Access of Uninitialized Pointer

Mozilla Firefox: Integer Overflow in Audio/Video Playback Component
CVE-2026-16408 9.8 - Critical - July 21, 2026

Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Integer Overflow or Wraparound

Firefox: Service Workers DOM Mitigation Bypass (CVE-2026-16407)
CVE-2026-16407 9.8 - Critical - July 21, 2026

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

Mitigation Bypass in Firefox Networking Component
CVE-2026-16406 9.1 - Critical - July 21, 2026

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

Info disclosure in Firefox WebSockets before v153/ESR140.13
CVE-2026-16405 7.5 - High - July 21, 2026

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Information Disclosure

Address Bar Spoofing Issue in Firefox
CVE-2026-16403 6.5 - Medium - July 21, 2026

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

User Interface (UI) Misrepresentation of Critical Information

Firefox Integer Overflow: ImageLib Component (Fixed in v153)
CVE-2026-16402 9.8 - Critical - July 21, 2026

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Integer Overflow or Wraparound

Firefox DLP Component Privilege Escalation (CVE-2026-16401)
CVE-2026-16401 8.8 - High - July 21, 2026

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Improper Privilege Management

Firefox DOM Security Component Info Disclosure (CVE-2026-16400)
CVE-2026-16400 7.5 - High - July 21, 2026

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Information Disclosure

Firefox DOM Navigation Site Isolation Vulnerability
CVE-2026-16399 7.5 - High - July 21, 2026

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Origin Validation Error

Firefox Graphics Site Isolation Flaw
CVE-2026-16398 7.5 - High - July 21, 2026

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Origin Validation Error

Firefox WebExtensions Privilege Escalation Fixed in v153 & ESR 140.13
CVE-2026-16396 8.8 - High - July 21, 2026

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Improper Privilege Management

Integer Overflow in Firefox AV Component
CVE-2026-16395 9.8 - Critical - July 21, 2026

Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Integer Overflow or Wraparound

Firefox DOM Mitigation Bypass in Security Component
CVE-2026-16394 9.1 - Critical - July 21, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

Firefox WebGPU Boundary Condition Vulnerability
CVE-2026-16393 9.1 - Critical - July 21, 2026

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Buffer Overflow

Firefox GMP Boundary Condition Vulnerability Fixed in 153/115.38/140.13
CVE-2026-16359 9.1 - Critical - July 21, 2026

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Buffer Overflow

Firefox JIT Engine Miscompilation CVE-2026-16392
CVE-2026-16392 9.1 - Critical - July 21, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Always-Incorrect Control Flow Implementation

Mozilla Firefox <153 ESR 140.13: IndexedDB Info Disclosure
CVE-2026-16391 7.5 - High - July 21, 2026

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Information Disclosure

Firefox Mitigation Bypass in Enterprise Policies (before 153 / ESR 140.13)
CVE-2026-16390 9.1 - Critical - July 21, 2026

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Protection Mechanism Failure

Integer overflow in Mozilla NSS Libraries
CVE-2026-16389 9.8 - Critical - July 21, 2026

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Integer Overflow or Wraparound

Firefox Sandbox Escape: DOM Networking Component
CVE-2026-16388 9.8 - Critical - July 21, 2026

Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

Site Isolation Issue in Firefox Networking Component (fixed in 153/140.13)
CVE-2026-16387 9.8 - Critical - July 21, 2026

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Origin Validation Error

CVE-2026-16386: WebGPU Uninitialized Memory Disclosure in Firefox
CVE-2026-16386 7.5 - High - July 21, 2026

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Use of Uninitialized Resource

Info Disclosure via Uninit Mem in Firefox WebGPU
CVE-2026-16385 7.5 - High - July 21, 2026

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Use of Uninitialized Resource

Firefox WebGPU Uninitialized Memory Disclosure
CVE-2026-16384 7.5 - High - July 21, 2026

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Use of Uninitialized Resource

Mitigation Bypass in Firefox DOM Networking (before 153/140.13)
CVE-2026-16383 9.8 - Critical - July 21, 2026

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Protection Mechanism Failure

Firefox service workers mitigation bypass (CVE-2026-16382)
CVE-2026-16382 9.8 - Critical - July 21, 2026

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

Firefox Same-Op Policy Bypass in Networking:DNS (pre-153/140.13)
CVE-2026-16381 9.1 - Critical - July 21, 2026

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Origin Validation Error

Mitigation bypass in Firefox Networking component
CVE-2026-16380 9.1 - Critical - July 21, 2026

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

CVE-2026-16358: FireFox WebRender Site Isolation Fix 153
CVE-2026-16358 9.8 - Critical - July 21, 2026

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Origin Validation Error

Privilege Escalation via DOM in Firefox 153/ESR 140.13
CVE-2026-16379 8.8 - High - July 21, 2026

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Improper Privilege Management

Firefox DOM Copy&Paste/Drag&Drop Issue
CVE-2026-16378 7.5 - High - July 21, 2026

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Improper Input Validation

Mitigation Bypass in Firefox PDF Viewer (before v153, ESR 140.13)
CVE-2026-16377 9.8 - Critical - July 21, 2026

Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Protection Mechanism Failure

DoS via WebGPU in Firefox
CVE-2026-16376 7.5 - High - July 21, 2026

Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Resource Exhaustion

Site Isolation Flaw in Firefox HTTP Network (fixed 153, ESR140.13)
CVE-2026-16375 9.8 - Critical - July 21, 2026

Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Origin Validation Error

Info Disclosure in Firefox DevTools Framework (153)
CVE-2026-16374 7.5 - High - July 21, 2026

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Information Disclosure

Privilege Escalation in Firefox DOM Content Process Component
CVE-2026-16372 8.8 - High - July 21, 2026

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Improper Privilege Management

Firefox 153 Priv Esc in DOM Nav Component
CVE-2026-16371 8.8 - High - July 21, 2026

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Improper Privilege Management

Firefox Networking Component DOM Mitigation Bypass
CVE-2026-16370 9.1 - Critical - July 21, 2026

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Protection Mechanism Failure

Firefox UAF Sandbox Escape in Disability Access APIs (pre153)
CVE-2026-16356 9.8 - Critical - July 21, 2026

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Dangling pointer

Boundary Cond. Bug in Firefox Graphics (Fixed before v153)
CVE-2026-16357 9.8 - Critical - July 21, 2026

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Buffer Overflow

Firefox JavaScript Engine JIT Miscompilation before v153
CVE-2026-16355 9.8 - Critical - July 21, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Object Type Confusion

Firefox 153 Integer Overflow in WebAssembly Component
CVE-2026-16369 9.8 - Critical - July 21, 2026

Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Integer Overflow or Wraparound

Firefox 153 WebAssembly Boundary Condition Flaw
CVE-2026-16368 9.8 - Critical - July 21, 2026

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Buffer Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mozilla Thunderbird or by Mozilla? Click the Watch button to subscribe.

Mozilla
Vendor

Mozilla Thunderbird
Email client

subscribe