ZeroHour

CVE-2026-84637

mass

Thunderbird calendar invitation flaw can launch local/network executables on Windows

CVSS 3.1
9.8 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-84637 is a flaw in Mozilla Thunderbird's handling of calendar invitations: an attachment in a malicious invitation using a file:// URI can cause Windows to launch a local or network-hosted executable, bypassing Thunderbird's normal protections on executable attachments. It is triggered when a crafted calendar invitation is processed; when the new invitation display is enabled, the attachment can additionally be shown under a misleading filename. An attacker gains the ability to run executables of their choosing on the victim's Windows machine, which can lead to malware execution; Mozilla rates the flaw 9.8 (critical). Affected users are those running Thunderbird on Windows in versions before 154, or the 153.x branch before 153.2. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.

What to do: Upgrade Windows installations of Thunderbird to version 154 or 153.2 (or later) as soon as possible. Until patched, treat calendar invitations from untrusted senders with caution, avoid opening or accepting file:// URI attachments in invitations, and consider not enabling the new invitation display, since it can present attachments under misleading filenames.

Affected
Mozilla ThunderbirdWindows; all versions prior to 154 and the 153.x branch prior to 153.2
Estimated exposure
mass≈20 million+ users (Thunderbird's publicly reported monthly active user base) — Thunderbird's publisher-reported monthly active user base runs to tens of millions, so the affected population is plausibly in the millions even after narrowing to Windows users on pre-154/153.2 builds who receive calendar invitations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.

Vendors
mozilla
Products
thunderbird
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.