Thunderbird
This hub aggregates every CVE we track for Thunderbird, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
1,962
CVEs tracked
680
Critical
605
High
14
In CISA KEV
Severity distribution
CRITICAL680MEDIUM651HIGH605LOW26
Monthly trend
9
23
17
0
9
13
13
24
16
12
16
7
10
11
16
13
17
51
47
50
37
42
66
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Thunderbird.
- CVE-2026-14899Off-by-one out of bounds read in MIME header parser for forwarding7.5
- CVE-2026-16361Memory safety bugs fixed in Thunderbird ESR 140.139.8
- CVE-2026-16360Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16412Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 1539.8
- CVE-2026-16411Memory safety bugs fixed in Firefox 1539.8
- CVE-2026-16410JIT miscompilation in the JavaScript Engine: JIT component9.8
- CVE-2026-16409Invalid pointer in the Security: PSM component7.5
- CVE-2026-16408Integer overflow in the Audio/Video: Playback component9.8
- CVE-2026-16407Mitigation bypass in the DOM: Service Workers component9.8
- CVE-2026-16406Mitigation bypass in the Networking component9.1
- CVE-2026-16405Information disclosure in the Networking: WebSockets component7.5
- CVE-2026-16403Spoofing issue in the Address Bar component6.5
- CVE-2026-16402Integer overflow in the Graphics: ImageLib component9.8
- CVE-2026-16401Privilege escalation in the Data Loss Prevention component8.8
- CVE-2026-16400Information disclosure in the DOM: Security component7.5
Product normalization is registry-driven with AI assist and human review. How it works