Junglewise Threat Intelligence

CVE-2026-84145: Mozilla Thunderbird memory corruption and security defects

CVE-2026-84145 · Severity: high · CVSS 7.5 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Thunderbird ESR. Vendors: Mozilla.

Executive brief

Thunderbird, a widely-used email and calendar client, contains multiple internally discovered bugs that can cause memory corruption or other security vulnerabilities. An attacker with sufficient effort could potentially exploit these flaws to crash the application, execute arbitrary code, or compromise user data and email communications. Mozilla has released patches to address these issues across multiple Thunderbird versions.

Technical details

This vulnerability encompasses multiple memory corruption and security-related defects discovered by Mozilla's internal security team in the Thunderbird email client. The bugs involve memory safety issues across multiple components in affected versions. The vulnerabilities require no user interaction beyond normal email client usage, as they can be triggered through malicious content or network interactions. An attacker can achieve code execution, denial of service, or information disclosure depending on the specific underlying defect. Patches are available in Thunderbird 155, 140.15, and 153.2.

Affected products

  • Mozilla Thunderbird 154
  • Mozilla Thunderbird ESR 153.1, 140.14

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Thunderbird 155, 140.15, and 153.2

References

Related threats