Known Vulnerabilities for Thunderbird by Mozilla
Listed below are 10 of the newest known vulnerabilities associated with "Thunderbird" by "Mozilla".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75874 json | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-74990 json | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-74989 json | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-74988 json | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corr... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-74987 json | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-74986 json | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 1... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-74985 json | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Th... | Not Provided | 2026-08-18 | 2026-08-21 |
| CVE-2026-74984 json | Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbir... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-74983 json | Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fir... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-74982 json | Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, a... | Not Provided | 2026-08-18 | 2026-08-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Thunderbird | 9.0.1 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 78.6.0 | |||
| Application | Mozilla | Thunderbird | 78.5.1 | |||
| Application | Mozilla | Thunderbird | 78.4.0 | |||
| Application | Mozilla | Thunderbird | 78.3 | |||
| Application | Mozilla | Thunderbird | 78.2 | |||
| Application | Mozilla | Thunderbird | 78.1.1 | |||
| Application | Mozilla | Thunderbird | 78.1.0 |