Junglewise Threat Intelligence

CVE-2026-84142: Mozilla Thunderbird memory corruption and security defects

CVE-2026-84142 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Executive brief

Thunderbird 154 contains multiple internally discovered bugs that demonstrate evidence of memory corruption and other security-relevant defects. These defects could potentially be exploited by an attacker to compromise the email client. The vulnerabilities were addressed in Thunderbird 155.

Technical details

Multiple memory corruption and security-relevant defects were identified in Thunderbird 154 through internal testing. The vulnerabilities span several bug reports and represent memory safety issues or other exploitable security flaws. The exact attack vectors and preconditions vary by individual bug, but collectively they posed enough risk that Mozilla prioritized fixes in Thunderbird 155. No evidence of active exploitation in the wild has been reported.

Affected products

  • Mozilla Thunderbird 154

Timeline

  • 2026-09-01: disclosed
  • 2026: patched: Fixed in Thunderbird 155

References

Related threats