CVE-2026-84143
massMemory corruption flaws in Mozilla Thunderbird 154 and Firefox releases before 155
CVE-2026-84143 covers internally discovered bugs in Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14, some of which showed evidence of memory corruption (CWE-119) or other security-relevant defects such as information exposure (CWE-200). Per the published CVSS 9.8 rating, the flaws are network-exploitable without privileges or user interaction, and Mozilla states that with enough effort some of them could have been exploited, potentially giving an attacker a high impact on confidentiality, integrity, and availability (e.g., code execution or data disclosure). Because fixes shipped in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2, users of Firefox releases prior to 155 and of the named Thunderbird releases are in scope. There is no evidence of exploitation in the wild: no public proof-of-concept exists, the issue is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days (31st percentile).
What to do: Update Firefox to 155 (or Firefox ESR 140.15/153.2) and Thunderbird to 155 (or Thunderbird ESR 140.15/153.2) as soon as practical; there are no configuration workarounds for memory-corruption defects, so prioritize Thunderbird deployments that process untrusted mail. Inventory browser and mail-client versions and confirm no endpoints remain on Thunderbird 154, Thunderbird ESR 153.1, Thunderbird ESR 140.14, or Firefox releases before 155.
| mozilla thunderbird | 154 (fixed in 155) |
| mozilla thunderbird esr | 153.1 (fixed in 153.2) |
| mozilla thunderbird esr | 140.14 (fixed in 140.15) |
| mozilla firefox | releases prior to 155 (fix shipped in 155) |
| mozilla firefox esr | releases prior to 140.15 and prior to 153.2 (fixes shipped in those ESR versions) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-119, CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.