Thunderbird
This hub aggregates every CVE we track for Thunderbird, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
2,125
CVEs tracked
729
Critical
687
High
14
In CISA KEV
Severity distribution
CRITICAL729HIGH687MEDIUM683LOW26
Monthly trend
23
17
0
9
13
13
24
16
12
16
7
10
11
16
13
17
51
47
50
37
42
66
55
108
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Thunderbird.
- CVE-2026-92240Out-of-bounds read in IMAP response parser9.1
- CVE-2026-92239Buffer overrun in IMAP8.1
- CVE-2026-92238Ambiguous parsing of mail headers9.8
- CVE-2026-92079Mitigation bypass in the Widget: Win32 component9.1
- CVE-2026-92078Denial-of-service in the Security component6.5
- CVE-2026-92077Denial-of-service in the SVG component6.5
- CVE-2026-92076Incorrect boundary conditions in the Networking component8.8
- CVE-2026-92075Mitigation bypass in the Networking component9.1
- CVE-2026-92074Mitigation bypass in the Popup Blocker component8.8
- CVE-2026-92073Privilege escalation in the Enterprise Policies component8.8
- CVE-2026-92072Incorrect boundary conditions in the Safe Browsing component8.0
- CVE-2026-92071Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component9.6
- CVE-2026-92070Information disclosure in the Networking component4.3
- CVE-2026-92069Spoofing issue in the DOM: Navigation component5.4
- CVE-2026-92068Site isolation issue in the Reader Mode component5.4
Product normalization is registry-driven with AI assist and human review. How it works