Thunderbird
Mozilla- Software type
- —
- Catalog vulnerabilities
- 2,007
Severity across 5 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 5 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, Thunderbird has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Thunderbird and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-84642Allowed UNC hostnames for attachments interpreted as a regular expression | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84641Information disclosure due to malicious IMAP server response | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84640One byte overflow read in mail parser | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84639Uninitialized memory in MIME parsing | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84637Calendar invitation attachments could launch local executables | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84144Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2 | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84143Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84142Internally found bugs fixed in Thunderbird 155 | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84141Integer overflow in the Graphics: ImageLib component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84140Site isolation issue in the DOM: Navigation component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84139Clickjacking issue in the DOM: Events component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84138Denial-of-service in the PDF Viewer component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84137Spoofing issue in the DOM: Core & HTML component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84136Other issue in the DOM: Navigation component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84134Other issue in the Profile Backup component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84133Site isolation issue in the DOM: Push Subscriptions component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84132Information disclosure in the Networking: HTTP component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84130Information disclosure in the Graphics: WebGPU component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84129Site isolation issue in the DOM: Navigation component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84128Privilege escalation in the WebDriver BiDi component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84126Incorrect boundary conditions in the Layout: Grid component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
CVE-2026-84125Use-after-free in the DOM: Core & HTML component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
CVE-2026-84124Use-after-free in the DOM: Core & HTML component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
CVE-2026-84123Privilege escalation due to use-after-free in the Graphics: WebGPU component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84122Use-after-free in the Audio/Video component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
CVE-2026-84118Use-after-free in the JavaScript: GC component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
CVE-2026-84145Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84131Privilege escalation due to invalid pointer in the Graphics component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityHigh |
CVE-2026-84121Sandbox escape due to use-after-free in the DOM: Security component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-84120Use-after-free in the Audio/Video component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityMedium |
CVE-2026-84119Sandbox escape due to use-after-free in the DOM: Navigation component | Exploitation statusNot known exploited | FixYes | Published09/01/2026 | SeverityCritical |
CVE-2026-74989Internally found bugs fixed in Thunderbird 154 | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74988Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74986Site isolation issue in the CSS Parsing and Computation component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74985Privilege escalation in the Enterprise Policies component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74984Race condition in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74982Denial-of-service in the Widget component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74981Site isolation issue in the Audio/Video: Web Codecs component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74979Mitigation bypass in the Add-ons Manager component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74978Clickjacking issue in the Widget component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74977Integer overflow in the Graphics component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74970Site isolation issue in the Graphics component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74968Site isolation issue in the Graphics: WebRender component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74966Information disclosure in the Form Autofill component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74961Side-channel in the Web Audio component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74958Information disclosure in the WebRTC component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74956Same-origin policy bypass in the DOM: Service Workers component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74955Privilege escalation in the Request Handling component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74954Information disclosure due to side-channel in the Storage: Cache API component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74952Privilege escalation in the Application Update component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74950Privilege escalation in the Downloads API component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74947Privilege escalation due to invalid pointer in the Graphics component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74938Mitigation bypass in the JavaScript: GC component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74937Use-after-free in the JavaScript: GC component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-75874Sandbox escape in the Remote Settings Client component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74990Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74987Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74983Mitigation bypass in the Data Loss Prevention component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74976JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74974Same-origin policy bypass in the Graphics: ImageLib component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74973Race condition, use-after-free in the Graphics component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74972Information disclosure in the DOM: Push Subscriptions component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74971Information disclosure in the DOM: UI Events & Focus Handling component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74969Use-after-free in the Layout: Text and Fonts component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74967Same-origin policy bypass in the Audio/Video: Playback component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74965Privilege escalation in the Shell Integration component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74964Integer overflow in the Graphics component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74963Same-origin policy bypass in the Networking: Cookies component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74962Site isolation issue in the Networking: Cookies component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74960Site isolation issue in the WebExtensions component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74959Mitigation bypass in the Storage: Cache API component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74957Mitigation bypass in the Safe Browsing component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74953Privilege escalation in the Networking: Cookies component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74949Privilege escalation due to use-after-free in the Graphics: Canvas2D component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74948Information disclosure in the Graphics component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74946Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74945Information disclosure in the Graphics: Text component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityMedium |
CVE-2026-74944Use-after-free in the DOM: Core & HTML component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74943Use-after-free in the Graphics: ImageLib component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74942Privilege escalation in the Remote Settings Client component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74941Privilege escalation in the Graphics: CanvasWebGL component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74940Use-after-free in the Graphics: Text component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74939Privilege escalation in the DOM: Navigation component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74936Use-after-free in the JavaScript: WebAssembly component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityCritical |
CVE-2026-74935Privilege escalation in the DOM: Networking component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-74934Site isolation issue in the Graphics: CanvasWebGL component | Exploitation statusNot known exploited | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-14899Off-by-one out of bounds read in MIME header parser for forwarding | Exploitation statusNot known exploited | FixYes | Published07/22/2026 | SeverityHigh |
CVE-2026-16361Memory safety bugs fixed in Thunderbird ESR 140.13 | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16360Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16412Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16411Memory safety bugs fixed in Firefox 153 | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16410JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16409Invalid pointer in the Security: PSM component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityHigh |
CVE-2026-16408Integer overflow in the Audio/Video: Playback component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16407Mitigation bypass in the DOM: Service Workers component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16406Mitigation bypass in the Networking component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16405Information disclosure in the Networking: WebSockets component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityHigh |
CVE-2026-16403Spoofing issue in the Address Bar component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityMedium |
CVE-2026-16402Integer overflow in the Graphics: ImageLib component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityCritical |
CVE-2026-16401Privilege escalation in the Data Loss Prevention component | Exploitation statusNot known exploited | FixYes | Published07/21/2026 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan