Mozilla Thunderbird Email client
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Mozilla Thunderbird.
Recent Mozilla Thunderbird Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-86 | Security Vulnerabilities fixed in Thunderbird 155 mfsa2026-86 | September 1, 2026 |
| mfsa2026-88 | Security Vulnerabilities fixed in Thunderbird 153.2 mfsa2026-88 | September 1, 2026 |
| mfsa2026-87 | Security Vulnerabilities fixed in Thunderbird 140.15 mfsa2026-87 | September 1, 2026 |
| mfsa2026-78 | Security Vulnerabilities fixed in Thunderbird 154 mfsa2026-78 | August 18, 2026 |
| mfsa2026-80 | Security Vulnerabilities fixed in Thunderbird 153.1 mfsa2026-80 | August 18, 2026 |
| mfsa2026-79 | Security Vulnerabilities fixed in Thunderbird 140.14 mfsa2026-79 | August 18, 2026 |
| mfsa2026-72 | Security Vulnerabilities fixed in Thunderbird 140.13 mfsa2026-72 | July 21, 2026 |
| mfsa2026-71 | Security Vulnerabilities fixed in Thunderbird 153 mfsa2026-71 | July 21, 2026 |
| mfsa2026-64 | Security Vulnerabilities fixed in Thunderbird 140.12.1 mfsa2026-64 | June 30, 2026 |
| mfsa2026-63 | Security Vulnerabilities fixed in Thunderbird 152.0.1 mfsa2026-63 | June 30, 2026 |
By the Year
In 2026 there have been 396 vulnerabilities in Mozilla Thunderbird with an average score of 7.9 out of ten. Last year, in 2025 Thunderbird had 157 security vulnerabilities published. That is, 239 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.22.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 396 | 7.88 |
| 2025 | 157 | 7.65 |
| 2024 | 119 | 7.15 |
| 2023 | 102 | 7.49 |
| 2022 | 116 | 7.56 |
| 2021 | 73 | 7.23 |
| 2020 | 80 | 7.59 |
| 2019 | 62 | 8.21 |
| 2018 | 167 | 8.24 |
It may take a day or so for new Thunderbird vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Thunderbird Security Vulnerabilities
Regex Injection via mail.allowed_attachment_hostnames in Thunderbird <155
CVE-2026-84642
7.5 - High
- September 01, 2026
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2.
ReDoS
Thunderbird IMAP use-after-free heap disclosure before 155
CVE-2026-84641
7.5 - High
- September 01, 2026
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Dangling pointer
Mail Header Buffer Overread (Read Past End) in Thunderbird <155 (fixed in 155)
CVE-2026-84640
7.5 - High
- September 01, 2026
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Buffer Over-read
Thunderbird Uninitialized Memory Use in MIME Bodies (before 155)
CVE-2026-84639
9.1 - Critical
- September 01, 2026
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Use of Uninitialized Variable
Thunderbird <=153: Windows Local Exec via File URI Calendar Invites
CVE-2026-84637
9.8 - Critical
- September 01, 2026
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
Unrestricted File Upload
Firefox 154/153.1 memcorr flaw (CVE-2026-84144)
CVE-2026-84144
7.5 - High
- September 01, 2026
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Buffer Overflow
Firefox <155 memory corruption CVE-2026-84143
CVE-2026-84143
9.8 - Critical
- September 01, 2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Information Disclosure
Memory Corruption in Firefox 154 (CVE-2026-84142)
CVE-2026-84142
9.8 - Critical
- September 01, 2026
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Information Disclosure
Firefox Integer Overflow in ImageLib (Graphics) Before v155
CVE-2026-84141
9.8 - Critical
- September 01, 2026
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Integer Overflow or Wraparound
Firefox 153.x+ Site Isolation DOM Navigation Vulnerability (CVE-2026-84140)
CVE-2026-84140
9.8 - Critical
- September 01, 2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Origin Validation Error
Firefox DOM Events clickjacking before v155
CVE-2026-84139
9.8 - Critical
- September 01, 2026
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Clickjacking
DoS in Firefox PDF Viewer (CVE-2026-84138)
CVE-2026-84138
7.5 - High
- September 01, 2026
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Resource Exhaustion
Firefox DOM Spoofing in Core & HTML Fixed in 155
CVE-2026-84137
9.8 - Critical
- September 01, 2026
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
User Interface (UI) Misrepresentation of Critical Information
Firefox DOM Navigation Component Vulnerability (Fixed in 155)
CVE-2026-84136
9.8 - Critical
- September 01, 2026
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Information Disclosure
Firefox 155+ Profile Backup component flaw (CVE-2026-84134)
CVE-2026-84134
9.8 - Critical
- September 01, 2026
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Information Disclosure
Firefox DOM Push Subscriptions site isolation flaw before v155
CVE-2026-84133
9.8 - Critical
- September 01, 2026
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Origin Validation Error
Firefox <155 Info Disclosure in Networking HTTP Component
CVE-2026-84132
7.5 - High
- September 01, 2026
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Information Disclosure
Firefox WebGPU Info Disclosure (before v155)
CVE-2026-84130
7.5 - High
- September 01, 2026
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Information Disclosure
Firefox SiteIsolation DOM Navigation Bug Fixed V155 ESR153.2
CVE-2026-84129
9.8 - Critical
- September 01, 2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Origin Validation Error
Firefox Privilege Escalation via WebDriver BiDi
CVE-2026-84128
8.8 - High
- September 01, 2026
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Authorization
Firefox Grid Layout Boundary Condition Vulnerability (CVE-2026-84126)
CVE-2026-84126
4.3 - Medium
- September 01, 2026
Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Classic Buffer Overflow
Use-After-Free in Firefox Core & HTML DOM Component <155
CVE-2026-84125
5.4 - Medium
- September 01, 2026
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Dangling pointer
Use-after-free in Firefox DOM: Core & HTML (before 155)
CVE-2026-84124
5.4 - Medium
- September 01, 2026
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Dangling pointer
Firefox Privilege Escalation via WebGPU Use-After-Free (before 155)
CVE-2026-84123
8.8 - High
- September 01, 2026
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Dangling pointer
UAF in Firefox Media Component (fixed 155/ESR 140.15/153.2)
CVE-2026-84122
5.4 - Medium
- September 01, 2026
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Dangling pointer
Use-after-Free in Firefox 155 JS GC component (before 155)
CVE-2026-84118
5.4 - Medium
- September 01, 2026
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Dangling pointer
Firefox 154 ESR 115.39 Memory Corruption Vulnerability
CVE-2026-84145
7.5 - High
- September 01, 2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Buffer Overflow
Firefox Priv Esc Prt Err in Graphics Comp (<155, ESR<115.40, ESR<140.15, ESR<153.2)
CVE-2026-84131
8.8 - High
- September 01, 2026
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Release of Invalid Pointer or Reference
Firefox Sandbox escape via DOM UAF (fixed in 155)
CVE-2026-84121
9.6 - Critical
- September 01, 2026
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Dangling pointer
Use-after-free in Audio/Video component of Firefox <155 (ESR 115.40)
CVE-2026-84120
5.4 - Medium
- September 01, 2026
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Dangling pointer
Firefox Sandbox Escape UAF in DOM Navigation Component
CVE-2026-84119
9.6 - Critical
- September 01, 2026
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Dangling pointer
Memory corruption bugs in Firefox 153
CVE-2026-74989
9.8 - Critical
- August 18, 2026
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Buffer Overflow
Firefox ESR 153.0 Memory Corruption Vulnerability (fixed in 153.1)
CVE-2026-74988
9.8 - Critical
- August 18, 2026
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Buffer Overflow
CSS Parsing Component Site Isolation Flaw Fixed in Firefox 154 & ESR 153.1
CVE-2026-74986
9.1 - Critical
- August 18, 2026
Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Information Disclosure
Firefox 154 ESR 153.1 Fixed PrivEsc in Enterprise Policies
CVE-2026-74985
9.8 - Critical
- August 18, 2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Race Condition in JS Engine, Firefox <154, fixed v154
CVE-2026-74984
6.8 - Medium
- August 18, 2026
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Race Condition
DoS in Firefox Widget component before 154/ESR153.1
CVE-2026-74982
7.5 - High
- August 18, 2026
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Resource Exhaustion
Site Isolation Vulnerability in Web Codecs (Firefox <154, Thunderbird <154)
CVE-2026-74981
8.1 - High
- August 18, 2026
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Mitigation bypass in Addons Manager (Firefox 154, ESR 153.1, Thunderbird 154)
CVE-2026-74979
9.8 - Critical
- August 18, 2026
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Authorization
Clickjacking in Firefox/Thunderbird widget component before v154
CVE-2026-74978
8.1 - High
- August 18, 2026
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Clickjacking
Site Isolation Flaw in WebRender of Firefox/Thunderbird (v<154)
CVE-2026-74968
5.4 - Medium
- August 18, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Firefox & Thunderbird Graphics INT Overflow CVE-2026-74977 Fixed 154
CVE-2026-74977
7.5 - High
- August 18, 2026
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Integer Overflow or Wraparound
Site isolation flaw in Firefox Graphics before v154
CVE-2026-74970
5.4 - Medium
- August 18, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Same-Origin Policy Bypass in Service Workers (Firefox <154, Thunderbird <154)
CVE-2026-74956
9.1 - Critical
- August 18, 2026
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Object Type Confusion
CVE-2026-74958: WebRTC Info Disclosure before Firefox+Thunderbird 154
CVE-2026-74958
7.5 - High
- August 18, 2026
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Clickjacking
Web Audio side-channel in Firefox 154, Thunderbird 154
CVE-2026-74961
9.1 - Critical
- August 18, 2026
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Side Channel Attack
Firefox 154: Information Disclosure in Form Autofill
CVE-2026-74966
7.5 - High
- August 18, 2026
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Privacy violation
Privilege Escalation via Request Handling in Firefox 154 & Thunderbird 154
CVE-2026-74955
8.8 - High
- August 18, 2026
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Mozilla Firefox AppUpd PrivEsc via Application Update Vulnerability
CVE-2026-74952
8.8 - High
- August 18, 2026
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2.
Improper Privilege Management
Firefox Storage Cache API Side-Channel Info Disclosure (fixed 154)
CVE-2026-74954
7.5 - High
- August 18, 2026
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Side Channel Attack
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Mozilla Thunderbird or by Mozilla? Click the Watch button to subscribe.