Description
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The advisory details internally found bugs in Thunderbird ESR 153.0 and Thunderbird 153. These bugs exhibited memory corruption or other security‑relevant defects, and the developers believe that with sufficient effort some could be exploited. While the precise exploitation path is not disclosed, the potential for memory corruption or a crash remains, indicating a high‑risk flaw.

Affected Systems

Mozilla's Thunderbird email client is affected, specifically the ESR 153.0 branch and the regular Thunderbird 153 release. Additionally, Mozilla's Firefox browser is impacted, with the ESR 153.1 and 154 releases containing the fix. Users running these versions on any platform face the risk. The updates that were applied, Thunderbird 154 and ESR 153.1, contain the fixes, so systems that have not upgraded remain vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a very high severity. The EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Based on the description, it is inferred that the bugs could lead to memory corruption, but the advisory does not mention a publicly available exploit, so the likelihood of exploitation remains uncertain. No publicly disclosed proof‑of‑concept has been reported, which implies that exploitation risk is low but not zero.

Generated by OpenCVE AI on September 2, 2026 at 06:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Thunderbird to version 154 or ESR 153.1, the releases that contain the fix for the identified bugs.
  • Upgrade Firefox to version 154 or ESR 153.1, the releases that contain the fix for the identified bugs.
  • Verify that no older or duplicate installations of Thunderbird 153 or ESR 153 remain on the system, removing them if present.
  • Maintain the operating system and any associated components or extensions at their latest patched states to reduce the chance that similar memory corruption issues could be leveraged elsewhere.

Generated by OpenCVE AI on September 2, 2026 at 06:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Title Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154

Mon, 24 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Title Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154

Fri, 21 Aug 2026 00:15:00 +0000


Thu, 20 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-416

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Title Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154
References

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-122
CWE-416
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:25:16.744Z

Reserved: 2026-08-17T11:59:23.074Z

Link: CVE-2026-74988

cve-icon Vulnrichment

Updated: 2026-08-20T15:49:29.960Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T13:17:40.687

Modified: 2026-09-01T22:17:12.190

Link: CVE-2026-74988

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T12:23:41Z

Links: CVE-2026-74988 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:00:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-130

    Improper Handling of Length Parameter Inconsistency