Calendar invitation attachments could launch local executables
Summary
| CVE | CVE-2026-84637 |
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-01 22:17:19 UTC |
| Updated | 2026-09-01 22:17:19 UTC |
| Description | Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. |
Vendor Declared Affected Products
Vendor Comments And Credit
Discovery Credit
CNA: Trung Nguyen (en)
There are currently no legacy QID mappings associated with this CVE.