Thunderbird Mozilla Thunderbird Email client

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mozilla Thunderbird.

Recent Mozilla Thunderbird Security Advisories

Advisory Title Published
mfsa2026-43 Security Vulnerabilities fixed in Thunderbird 150.0.2 mfsa2026-43 May 8, 2026
mfsa2026-44 Security Vulnerabilities fixed in Thunderbird 140.10.2 mfsa2026-44 May 8, 2026
mfsa2026-38 Security Vulnerabilities fixed in Thunderbird 150.0.1 mfsa2026-38 April 30, 2026
mfsa2026-39 Security Vulnerabilities fixed in Thunderbird 140.10.1 mfsa2026-39 April 30, 2026
mfsa2026-34 Security Vulnerabilities fixed in Thunderbird 140.10 mfsa2026-34 April 21, 2026
mfsa2026-33 Security Vulnerabilities fixed in Thunderbird 150 mfsa2026-33 April 21, 2026
mfsa2026-28 Security Vulnerabilities fixed in Thunderbird 149.0.2 mfsa2026-28 April 7, 2026
mfsa2026-29 Security Vulnerabilities fixed in Thunderbird 140.9.1 mfsa2026-29 April 7, 2026
mfsa2026-24 Security Vulnerabilities fixed in Thunderbird 140.9 mfsa2026-24 March 24, 2026
mfsa2026-23 Security Vulnerabilities fixed in Thunderbird 149 mfsa2026-23 March 24, 2026

By the Year

In 2026 there have been 170 vulnerabilities in Mozilla Thunderbird with an average score of 8.3 out of ten. Last year, in 2025 Thunderbird had 157 security vulnerabilities published. That is, 13 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.62.




Year Vulnerabilities Average Score
2026 170 8.28
2025 157 7.65
2024 119 7.19
2023 102 7.49
2022 116 7.56
2021 73 7.23
2020 80 7.59
2019 62 8.21
2018 167 8.24

It may take a day or so for new Thunderbird vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Thunderbird Security Vulnerabilities

Firefox ESR 140.10.2 WebRTC Vulnerability
CVE-2026-8094 9.8 - Critical - May 07, 2026

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Code Injection

Firefox 150.0.1 Memcor bugs may allow arbitrary code execution
CVE-2026-8093 8.1 - High - May 07, 2026

Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.

Buffer Overflow

Firefox 115.35.1/140.10.1/150.0.1 Memory Safety Bug
CVE-2026-8092 8.1 - High - May 07, 2026

Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Out-of-bounds Read

Firefox ESR AV Playback boundary flaw before 140.10.2
CVE-2026-8091 9.8 - Critical - May 07, 2026

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

Improper Check for Unusual or Exceptional Conditions

Use-after-free in Firefox DOM Networking pre-150.0.2
CVE-2026-8090 7.3 - High - May 07, 2026

Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Dangling pointer

Firefox Sandbox Escape in WebRTC Networking before ESR 140.10.1
CVE-2026-7321 9.6 - Critical - April 28, 2026

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

Classic Buffer Overflow

Memory safety bugs in Firefox 150.0.0 (fixed 150.0.1)
CVE-2026-7324 7.3 - High - April 28, 2026

Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.

Buffer Overflow

Memory Safety Bug in Firefox ESR 140.10.0 & Thunderbird 140.10.0
CVE-2026-7323 7.3 - High - April 28, 2026

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

Buffer Overflow

Memory safety bugs in Firefox ESR 115.35.0/140.10.0 & 150.0.0 (fixed 150.0.1)
CVE-2026-7322 7.3 - High - April 28, 2026

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

Buffer Overflow

Firefox Audio/Video Boundary Bug Info Disclosure (fixed in 150.0.1)
CVE-2026-7320 7.5 - High - April 28, 2026

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

Buffer Overflow

Firefox 149 / ESR 140.9 Memory Safety Bugs (Arbitrary Code Exec)
CVE-2026-6786 8.1 - High - April 21, 2026

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Dangling pointer

Mozilla Firefox Memory Safety Bug (ESR 115.34, 115.35, ESR 140.9/140.10, 149)
CVE-2026-6785 8.1 - High - April 21, 2026

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Out-of-bounds Read

Memory Safety Bugs in Firefox 149 & Thunderbird 149
CVE-2026-6784 7.5 - High - April 21, 2026

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Out-of-bounds Read

Firefox 150 AV Playback CVE20266783 Integer Overflow
CVE-2026-6783 5.3 - Medium - April 21, 2026

Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Integer Overflow or Wraparound

Info Disclosure via Firefox IP Protection Component
CVE-2026-6782 7.5 - High - April 21, 2026

Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Information Disclosure

DoS in Firefox AV Playback Component (CVE-2026-6781)
CVE-2026-6781 7.5 - High - April 21, 2026

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Resource Exhaustion

Firefox A/V Playback DoS Vulnerability
CVE-2026-6780 7.5 - High - April 21, 2026

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Resource Exhaustion

Mozilla Firefox JS Engine CVE-2026-6779 (Other issue)
CVE-2026-6779 5.3 - Medium - April 21, 2026

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Buffer Overflow

Firefox 150 - Invalid Pointer in Audio/Video Playback
CVE-2026-6778 5.3 - Medium - April 21, 2026

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Access of Uninitialized Pointer

CVE-2026-6777: Firefox DNS Component Vulnerability
CVE-2026-6777 5.3 - Medium - April 21, 2026

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Improper Input Validation

Firefox <150 WebRTC Networking boundary condition flaw (CVE-2026-6776)
CVE-2026-6776 7.8 - High - April 21, 2026

Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Buffer Overflow

Firefox WebRTC Improper Boundary Check (CVE-2026-6775)
CVE-2026-6775 5.3 - Medium - April 21, 2026

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Buffer Overflow

DOM Mitigation Bypass in Firefox Security Component
CVE-2026-6774 5.4 - Medium - April 21, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Protection Mechanism Failure

Firefox NSS Libraries Boundary Cond. before 150
CVE-2026-6772 7.5 - High - April 21, 2026

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Improper Check for Unusual or Exceptional Conditions

Firefox WebGPU Integer Overflow DoS
CVE-2026-6773 7.5 - High - April 21, 2026

Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Integer Overflow or Wraparound

Firefox 150 DOM Mitigation Bypass in Security Component
CVE-2026-6771 9.8 - Critical - April 21, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Authentication Bypass Using an Alternate Path or Channel

IndexedDB flaw in Firefox <=150 (ESR 140.10)
CVE-2026-6770 6.5 - Medium - April 21, 2026

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Information Disclosure

Priv Escalation in Firefox Debugger (before 150)
CVE-2026-6769 8.8 - High - April 21, 2026

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Improper Privilege Management

CVE-2026-6768: Mitigation Bypass in Firefox Cookies Handling
CVE-2026-6768 9.8 - Critical - April 21, 2026

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Authentication Bypass Using an Alternate Path or Channel

NSS Lib Other Issue (Fixed in Firefox 150/ESR 115.35)
CVE-2026-6767 5.3 - Medium - April 21, 2026

Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Buffer Overflow

Firefox NSS boundary overflow (before 150/140.10)
CVE-2026-6766 7.5 - High - April 21, 2026

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Improper Check for Unusual or Exceptional Conditions

Firefox Autofill Info Disclosure before 150
CVE-2026-6765 5.3 - Medium - April 21, 2026

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Privacy violation

Firefox DOM Boundary Condition Flaw in Device Interfaces (fixed in v150)
CVE-2026-6764 6.5 - Medium - April 21, 2026

Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Buffer Overflow

Firefox File Handling Mitigation Bypass (Before 150/ESR 140.10)
CVE-2026-6763 6.5 - Medium - April 21, 2026

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Protection Mechanism Failure

Firefox DOM Spoofing Vulnerability (pre-150) Core & HTML
CVE-2026-6762 6.3 - Medium - April 21, 2026

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Authentication Bypass by Spoofing

Firefox 150 PrivEsc via Networking Component
CVE-2026-6761 8.8 - High - April 21, 2026

Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Improper Privilege Management

Firefox Networking Cookies Mitigation Bypass CVE-2026-6760
CVE-2026-6760 9.8 - Critical - April 21, 2026

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Authentication Bypass Using an Alternate Path or Channel

Use-after-free in Firefox Widget Cocoa (150)
CVE-2026-6759 7.5 - High - April 21, 2026

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Dangling pointer

Use-after-free: WebAssembly Component in Firefox
CVE-2026-6758 7.5 - High - April 21, 2026

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Dangling pointer

Firefox WebAsm Null Pointer Bug Before v150 (CVE-2026-6757)
CVE-2026-6757 6.3 - Medium - April 21, 2026

Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Access of Uninitialized Pointer

Mozilla Firefox postMessage DOM Mitigation Bypass (CVE20266755)
CVE-2026-6755 6.5 - Medium - April 21, 2026

Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Session Riding

UAF in JavaScript Engine, fixed in Firefox 150/ESR 115.35/140.10
CVE-2026-6754 7.5 - High - April 21, 2026

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Dangling pointer

Firefox WebRTC Boundary Condition Vulnerability (fixed in 150/ESR 140.10)
CVE-2026-6753 7.3 - High - April 21, 2026

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Buffer Overflow

Firefox WebRTC Boundary Condition Flaw (before v150 / ESR 115.35)
CVE-2026-6752 7.3 - High - April 21, 2026

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Buffer Overflow

Pre-150 Firefox Web Codecs Uninitialized Memory Vulnerability
CVE-2026-6751 7.3 - High - April 21, 2026

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Use of Uninitialized Variable

Firefox PrivEsc via Graphics:WebRender before 150
CVE-2026-6750 8.8 - High - April 21, 2026

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Improper Privilege Management

Firefox Canvas2D Info Disclosure via Uninit Mem, Fixed 150/ESR115.35
CVE-2026-6749 7.5 - High - April 21, 2026

Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Use of Uninitialized Resource

Web Codecs Uninitialized Mem in Firefox <150 (Fixed 150)
CVE-2026-6748 9.8 - Critical - April 21, 2026

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Use of Uninitialized Variable

Firefox <150 WebRTC Use-after-free Vulnerability
CVE-2026-6747 7.5 - High - April 21, 2026

Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Dangling pointer

Use-after-free in Firefox Core&HTML before v150
CVE-2026-6746 7.5 - High - April 21, 2026

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Dangling pointer

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mozilla Thunderbird or by Mozilla? Click the Watch button to subscribe.

Mozilla
Vendor

Mozilla Thunderbird
Email client

subscribe