ZeroHour

Vulnerabilities

93 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-84637
+4 in the same advisory: …84639 …84641 …84640 …84642
Thunderbird calendar invitation flaw can launch local/network executables on Windows

CVE-2026-84637 is a flaw in Mozilla Thunderbird's handling of calendar invitations: an attachment in a malicious invitation using a file:// URI can cause Windows to launch a local or network-hosted executable, bypassing Thunderbird's normal protections on executable attachments. It is triggered when a crafted calendar invitation is processed; when the new invitation display is enabled, the attachment can additionally be shown under a misleading filename. An attacker gains the ability to run executables of their choosing on the victim's Windows machine, which can lead to malware execution; Mozilla rates the flaw 9.8 (critical). Affected users are those running Thunderbird on Windows in versions before 154, or the 153.x branch before 153.2. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.

Do: Upgrade Windows installations of Thunderbird to version 154 or 153.2 (or later) as soon as possible. Until patched, treat calendar invitations from untrusted senders with caution, avoid opening or accepting file:// URI attachments in invitations, and consider not enabling the new invitation display, since it can present attachments under misleading filenames.

9.8
group max
<1%
  • Mozilla Thunderbird Windows; all versions prior to 154 and the 153.x branch prior to 153.2
mass≈20 million+ users (Thunderbird's publicly reported monthly active user base)
CVE-2026-84143
Memory corruption flaws in Mozilla Thunderbird 154 and Firefox releases before 155

CVE-2026-84143 covers internally discovered bugs in Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14, some of which showed evidence of memory corruption (CWE-119) or other security-relevant defects such as information exposure (CWE-200). Per the published CVSS 9.8 rating, the flaws are network-exploitable without privileges or user interaction, and Mozilla states that with enough effort some of them could have been exploited, potentially giving an attacker a high impact on confidentiality, integrity, and availability (e.g., code execution or data disclosure). Because fixes shipped in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2, users of Firefox releases prior to 155 and of the named Thunderbird releases are in scope. There is no evidence of exploitation in the wild: no public proof-of-concept exists, the issue is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days (31st percentile).

Do: Update Firefox to 155 (or Firefox ESR 140.15/153.2) and Thunderbird to 155 (or Thunderbird ESR 140.15/153.2) as soon as practical; there are no configuration workarounds for memory-corruption defects, so prioritize Thunderbird deployments that process untrusted mail. Inventory browser and mail-client versions and confirm no endpoints remain on Thunderbird 154, Thunderbird ESR 153.1, Thunderbird ESR 140.14, or Firefox releases before 155.

9.8
group max
<1%
  • mozilla thunderbird 154 (fixed in 155)
  • mozilla thunderbird esr 153.1 (fixed in 153.2)
  • mozilla thunderbird esr 140.14 (fixed in 140.15)
  • +2 more
masson the order of hundreds of millions of users (combined Firefox and Thunderbird install base)
CVE-2026-84135
+2 in the same advisory: …84117 …84127
Input Validation Flaw Exposing Sensitive Data in Firefox Focus for Android

Mozilla has disclosed CVE-2026-84135, a critical (CVSS 9.8) issue in Firefox Focus for Android that the advisory characterizes only as an "other issue," with associated weaknesses of improper input validation (CWE-20) and exposure of sensitive information (CWE-200). According to the CVSS vector, the flaw can be triggered remotely over the network without privileges or user interaction, although Mozilla has not publicly detailed the precise attack path. Successful exploitation could allow an attacker to read or modify sensitive data and affect availability, consistent with the high confidentiality, integrity, and availability impact ratings in the score. Android users running affected versions of Firefox Focus are in scope, and the vulnerability was fixed in the Firefox 155 release. There is currently no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is known.

Do: Update Firefox Focus for Android to the Firefox 155 release or later via Google Play, and verify that managed Android fleets are running the patched build; no workarounds are noted in the advisory. Given there is no evidence of active exploitation, this is routine patching rather than emergency response, but the critical 9.8 score warrants prompt action.

9.8
group max
<1%
  • mozilla Firefox Focus for Android (Firefox mobile) Versions prior to 155 (fixed in Firefox 155)
mass≈10 million+ Android users (Firefox Focus lists 10M+ Google Play installs)
CVE-2026-81267
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to re

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.

NVD description · AI analysis pending
5.4<1%
  • mozilla firefox mobile
CVE-2026-75874
Sandbox escape in the Remote Settings Client component.

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.

NVD description · AI analysis pending
10.0
group max
<1%
  • mozilla firefox
  • mozilla thunderbird
CVE-2026-74980
Clickjacking issue in the Downloads component in Firefox for Android.

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

NVD description · AI analysis pending
6.5<1%
  • mozilla firefox mobile