Thunderbird
This hub aggregates every CVE we track for Thunderbird, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
2,048
CVEs tracked
708
Critical
641
High
14
In CISA KEV
Severity distribution
CRITICAL708MEDIUM673HIGH641LOW26
Monthly trend
23
17
0
9
13
13
24
16
12
16
7
10
11
16
13
17
51
47
50
37
42
66
55
31
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Thunderbird.
- CVE-2026-84641Information disclosure due to malicious IMAP server response7.5
- CVE-2026-84642Allowed UNC hostnames for attachments interpreted as a regular expression7.5
- CVE-2026-84640One byte overflow read in mail parser7.5
- CVE-2026-84639Uninitialized memory in MIME parsing9.1
- CVE-2026-84637Calendar invitation attachments could launch local executables9.8
- CVE-2026-84144Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.27.5
- CVE-2026-84143Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.159.8
- CVE-2026-84142Internally found bugs fixed in Thunderbird 1559.8
- CVE-2026-84141Integer overflow in the Graphics: ImageLib component9.8
- CVE-2026-84140Site isolation issue in the DOM: Navigation component9.8
- CVE-2026-84139Clickjacking issue in the DOM: Events component6.1
- CVE-2026-84138Denial-of-service in the PDF Viewer component6.5
- CVE-2026-84137Spoofing issue in the DOM: Core & HTML component4.3
- CVE-2026-84136Other issue in the DOM: Navigation component6.1
- CVE-2026-84134Other issue in the Profile Backup component9.8
Product normalization is registry-driven with AI assist and human review. How it works