CVE-2026-84144
massMemory corruption bugs in Mozilla Firefox and Thunderbird
CVE-2026-84144 describes a set of internally discovered bugs in the shared Gecko codebase, present in Thunderbird 154 and Thunderbird ESR 153.1, showing evidence of memory corruption or another security-relevant defect (CWE-119). The flaws are network-reachable but require user interaction and have high attack complexity, so exploitation is not straightforward; with enough effort, an attacker could potentially achieve high-impact effects on confidentiality, integrity, and availability, likely including code execution. Users running the affected Thunderbird releases, and the corresponding Firefox releases whose code received the same fixes, are exposed until they update. The bugs were fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. No public proof-of-concept is known, the issue is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade to Firefox 155, Firefox ESR 153.2, Thunderbird 155, or Thunderbird 153.2 (ESR 153.2). Use software inventory or endpoint management to confirm no managed systems remain on Thunderbird 154/ESR 153.1 or pre-155 Firefox builds; no workarounds are specified, so updating is the primary mitigation.
| Mozilla Firefox | prior to 155 |
| Mozilla Firefox ESR | prior to 153.2 |
| Mozilla Thunderbird | 154 and all versions prior to 155 |
| Mozilla Thunderbird ESR | 153.1 and all versions prior to 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.