CVE-2026-84637
massThunderbird calendar invitation flaw can launch local/network executables on Windows
CVE-2026-84637 is a flaw in Mozilla Thunderbird's handling of calendar invitations: an attachment in a malicious invitation using a file:// URI can cause Windows to launch a local or network-hosted executable, bypassing Thunderbird's normal protections on executable attachments. It is triggered when a crafted calendar invitation is processed; when the new invitation display is enabled, the attachment can additionally be shown under a misleading filename. An attacker gains the ability to run executables of their choosing on the victim's Windows machine, which can lead to malware execution; Mozilla rates the flaw 9.8 (critical). Affected users are those running Thunderbird on Windows in versions before 154, or the 153.x branch before 153.2. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.
What to do: Upgrade Windows installations of Thunderbird to version 154 or 153.2 (or later) as soon as possible. Until patched, treat calendar invitations from untrusted senders with caution, avoid opening or accepting file:// URI attachments in invitations, and consider not enabling the new invitation display, since it can present attachments under misleading filenames.
| Mozilla Thunderbird | Windows; all versions prior to 154 and the 153.x branch prior to 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- thunderbird
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.