Mozilla Foundation Security Advisory 2026-79
Security Vulnerabilities fixed in Thunderbird 140.14
- Announced
- August 18, 2026
- Impact
- high
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 140.14
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
- Reporter
- satyamasd
- Impact
- high
References
#CVE-2026-74935: Privilege escalation in the DOM: Networking component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74939: Privilege escalation in the DOM: Navigation component
- Reporter
- choeseyeong
- Impact
- high
References
#CVE-2026-74940: Use-after-free in the Graphics: Text component
- Reporter
- kiyong
- Impact
- high
References
#CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
- Reporter
- Jacolon Walker
- Impact
- high
References
#CVE-2026-74942: Privilege escalation in the Remote Settings Client component
- Reporter
- Gal Ankonina
- Impact
- high
References
#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- high
References
#CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74945: Information disclosure in the Graphics: Text component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- high
References
#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- locust1b
- Impact
- high
References
#CVE-2026-74948: Information disclosure in the Graphics component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component
- Reporter
- r00tdaddy
- Impact
- high
References
#CVE-2026-74953: Privilege escalation in the Networking: Cookies component
- Reporter
- Satoki Tsuji
- Impact
- moderate
References
#CVE-2026-74957: Mitigation bypass in the Safe Browsing component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
- Reporter
- David Bors at Snyk Security Labs
- Impact
- moderate
References
#CVE-2026-74960: Site isolation issue in the WebExtensions component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-74962: Site isolation issue in the Networking: Cookies component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-74964: Integer overflow in the Graphics component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-74965: Privilege escalation in the Shell Integration component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
- Reporter
- Hyeonjun Ahn
- Impact
- moderate
References
#CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
- Reporter
- avlidienbrunn
- Impact
- moderate
References
#CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
- Reporter
- Kagami Rosylight
- Impact
- moderate
References
#CVE-2026-74973: Race condition, use-after-free in the Graphics component
- Reporter
- r00tdaddy
- Impact
- moderate
References
#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
- Reporter
- anbu
- Impact
- low
References
#CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Reporter
- Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Moderate Severity internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Low Severity internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
#CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Reporter
- Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.