Description
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability consists of a set of internally discovered bugs that were present in Thunderbird ESR 140.13, Thunderbird ESR 153.0, and Thunderbird 153. Some of these bugs involve memory corruption or other security-relevant defects. The description indicates that, with sufficient effort, some of these could be exploited, potentially enabling arbitrary code execution. The fixes were applied in Thunderbird 154, Thunderbird ESR 140.14, and Thunderbird ESR 153.1.

Affected Systems

Affected systems are Mozilla's Thunderbird email client, specifically the Extended Support Release 140.13, the Extended Support Release 153.0, and the standard Thunderbird 153 release, as well as Mozilla Firefox older than version 154 (including releases prior to the Firefox ESR 140.14 and ESR 153.1). These bugs were corrected in subsequent releases: Thunderbird ESR 140.14, ESR 153.1, and Thunderbird 154, and Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1; users running earlier builds are at risk until they update.

Risk and Exploitability

Risk assessment can rely on the CVSS score of 9.8, which indicates a high severity of potential arbitrary code execution via memory corruption. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploits yet. Memory‑corruption vulnerabilities are high risk as they may enable arbitrary code execution if an attacker can trigger them; the likely attack vector could be remote or local, depending on how the corruption is triggered, though this is inferred because the description does not specify the exact trigger.

Generated by OpenCVE AI on September 2, 2026 at 06:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Thunderbird to version 154, ESR 140.14, or ESR 153.1
  • Upgrade Mozilla Firefox to version 154 or newer
  • Enable operating‑system mitigations such as ASLR and stack canaries to reduce the impact of any remaining memory corruption issues
  • Monitor security advisories from Mozilla for additional updates and review system logs for anomalous activity that might indicate exploitation attempts

Generated by OpenCVE AI on September 2, 2026 at 06:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Title Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154

Mon, 24 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Title Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Fri, 21 Aug 2026 00:15:00 +0000


Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Title Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:25:07.075Z

Reserved: 2026-08-17T11:59:22.495Z

Link: CVE-2026-74987

cve-icon Vulnrichment

Updated: 2026-08-19T13:05:34.146Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T13:17:40.560

Modified: 2026-09-01T22:17:12.020

Link: CVE-2026-74987

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T12:23:34Z

Links: CVE-2026-74987 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:00:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write