Junglewise Threat Intelligence

CVE-2026-74989: Mozilla Thunderbird memory corruption in version 153

CVE-2026-74989 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Thunderbird, a widely-used email and calendar client, contained multiple internally discovered security bugs in version 153 that could lead to memory corruption. These vulnerabilities could potentially allow attackers to execute arbitrary code or crash the application, affecting users' email security and system stability.

Technical details

Thunderbird 153 contained multiple memory corruption and security-relevant defects discovered during internal review. The vulnerabilities affect the Thunderbird email client itself and were fixed in version 154. While the specific attack vectors are not detailed in available documentation, memory corruption bugs typically allow remote code execution when triggered through malicious email content or attachments. No evidence of active exploitation in the wild has been reported, but the CVSS 9.8 score indicates high severity. Patches are available in Thunderbird 154 and later.

Affected products

  • Mozilla Thunderbird 153

Timeline

  • 2026-08-18: disclosed
  • 2026-08: patched: Fixed in Thunderbird 154

References

Related threats