ZeroHour

CVE-2026-84143

mass

Memory corruption flaws in Mozilla Thunderbird 154 and Firefox releases before 155

CVSS 3.1
9.8 critical
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-84143 covers internally discovered bugs in Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14, some of which showed evidence of memory corruption (CWE-119) or other security-relevant defects such as information exposure (CWE-200). Per the published CVSS 9.8 rating, the flaws are network-exploitable without privileges or user interaction, and Mozilla states that with enough effort some of them could have been exploited, potentially giving an attacker a high impact on confidentiality, integrity, and availability (e.g., code execution or data disclosure). Because fixes shipped in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2, users of Firefox releases prior to 155 and of the named Thunderbird releases are in scope. There is no evidence of exploitation in the wild: no public proof-of-concept exists, the issue is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days (31st percentile).

What to do: Update Firefox to 155 (or Firefox ESR 140.15/153.2) and Thunderbird to 155 (or Thunderbird ESR 140.15/153.2) as soon as practical; there are no configuration workarounds for memory-corruption defects, so prioritize Thunderbird deployments that process untrusted mail. Inventory browser and mail-client versions and confirm no endpoints remain on Thunderbird 154, Thunderbird ESR 153.1, Thunderbird ESR 140.14, or Firefox releases before 155.

Affected
mozilla thunderbird154 (fixed in 155)
mozilla thunderbird esr153.1 (fixed in 153.2)
mozilla thunderbird esr140.14 (fixed in 140.15)
mozilla firefoxreleases prior to 155 (fix shipped in 155)
mozilla firefox esrreleases prior to 140.15 and prior to 153.2 (fixes shipped in those ESR versions)
Estimated exposure
masson the order of hundreds of millions of users (combined Firefox and Thunderbird install base) — Firefox holds roughly 2-3% of the global desktop browser market (hundreds of millions of active users) and Thunderbird has tens of millions of active installs, and the affected versions include the then-current releases of both, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-119, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.