Junglewise Threat Intelligence

CVE-2026-84637: Mozilla Thunderbird calendar invitation code execution on Windows

CVE-2026-84637 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Executive brief

Thunderbird is an email and calendar client used for personal and business communication. An attacker can send a malicious calendar invitation with a file URI attachment that bypasses Thunderbird's protections and launches executables on a Windows computer, potentially leading to malware installation or system compromise. The vulnerability can also display the attachment under a misleading filename to trick users into opening it.

Technical details

This vulnerability is an attachment handling bypass in Thunderbird's calendar invitation processing. The root cause is insufficient validation of file URI attachments in calendar invitations on Windows, allowing attackers to bypass the normal executable attachment protections. The attack requires a user to receive and interact with a malicious calendar invitation; no authentication or network access beyond email delivery is required. An attacker can execute arbitrary local or network-hosted executables with the privileges of the Thunderbird process. The vulnerability was fixed in Thunderbird 154 and 153.2.

Affected products

  • Mozilla Thunderbird before 153.2 and before 154

Timeline

  • 2026-08-18: disclosed: Announced in Mozilla Security Advisory MFSA2026-78
  • 2026: patched: Fixed in Thunderbird 154 and 153.2

References

Related threats