Mozilla Foundation Security Advisory 2026-87
Security Vulnerabilities fixed in Thunderbird 140.15
- Announced
- September 1, 2026
- Impact
- high
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 140.15
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
#CVE-2026-84639: Uninitialized memory in MIME parsing
- Reporter
- Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
- Impact
- high
Description
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used.
References
#CVE-2026-84640: One byte overflow read in mail parser
- Reporter
- Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
- Impact
- medium
Description
A maliciously constructed mail header could lead to a one byte read past the end of a buffer.
References
#CVE-2026-84641: Information disclosure due to malicious IMAP server response
- Reporter
- ABDULAZIZ ALASAIQAH
- Impact
- low
Description
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js.
References
#CVE-2026-75874: Sandbox escape in the Remote Settings Client component
- Reporter
- crixer
- Impact
- high
References
#CVE-2026-16365: Privilege escalation in the DOM: Workers component
- Reporter
- Khanh Nguyen
- Impact
- high
References
#CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84120: Use-after-free in the Audio/Video component
- Reporter
- Ukyo Akai
- Impact
- high
References
#CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84122: Use-after-free in the Audio/Video component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-16371: Privilege escalation in the DOM: Navigation component
- Reporter
- Steven Julian
- Impact
- moderate
References
#CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component
- Reporter
- navapon
- Impact
- moderate
References
#CVE-2026-84143: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Reporter
- Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Moderate Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Low Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
#CVE-2026-84145: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Moderate Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- Low Severity internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15