CVE-2026-84145
massMemory corruption bugs in Mozilla Thunderbird and Firefox fixed in 155/153.2/140.15
Mozilla fixed a set of internally discovered bugs in Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14, several of which showed evidence of memory corruption (CWE-119) that Mozilla presumes could be exploited with sufficient attacker effort. Because Thunderbird and Firefox share the affected code, fixes were shipped for both products; the bugs would be triggered by untrusted content such as a malicious web page, email message, or attachment opened in the application, with user interaction required. Successful exploitation could yield a high-impact compromise of confidentiality, integrity, and availability (CVSS 3.1: 7.5 high, with network vector, high attack complexity, and no privileges required). Anyone running the affected builds — Thunderbird 154, ESR 153.1, or ESR 140.14, and Firefox releases preceding the fixed builds 155 and ESR 115.40/140.15/153.2 — is affected. There is no evidence of exploitation in the wild and no public proof-of-concept; EPSS estimates roughly a 0.4% chance of exploitation within 30 days.
What to do: Upgrade Firefox to 155, or on the ESR branches to 115.40, 140.15, or 153.2, and upgrade Thunderbird to 155, 153.2, or 140.15 as applicable to your branch. Inventory managed endpoints for Thunderbird 154/ESR 153.1/ESR 140.14 and the corresponding Firefox builds, prioritizing mail clients since email-borne content is a likely trigger. No public exploits or workarounds are known, so prompt patching before users open untrusted content is the primary mitigation.
| mozilla thunderbird | Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14; fixed in Thunderbird 155, Thunderbird 153.2, and Thunderbird 140.15 |
| mozilla firefox | Builds predating the fixed releases: Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2 (the advisory enumerates the fixed versions; ind |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.