Description
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Internally discovered bugs in Thunderbird 153 caused memory corruption or other security‑relevant defects, and the vendor presumes that, with sufficient effort, these could have been exploited to achieve arbitrary code execution. The vulnerability was addressed in Firefox 154 and Thunderbird 154.

Affected Systems

Mozilla Firefox 153 and Mozilla Thunderbird 153 are affected. These vulnerabilities were fixed in version 154 of each product. Users of Firefox 154 or later, or Thunderbird 154 or later, are not impacted.

Risk and Exploitability

The CVSS score of 9.8 indicates a very high severity. The EPSS score of less than 1% implies a low likelihood of exploitation in the wild, though a dedicated attacker could still target these flaws. The vulnerability involves memory corruption; the likely attack vector is input‑based, such as malicious email attachments, web content, or extensions, but the exact method is not documented. The likely attack vector is inferred from the description. The flaw is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 2, 2026 at 06:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 154 or later as soon as possible.
  • Upgrade Mozilla Thunderbird to version 154 or later as soon as possible.
  • Enable automatic updates for both Firefox and Thunderbird so future patches are applied without manual intervention.

Generated by OpenCVE AI on September 2, 2026 at 06:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Title Internally found bugs fixed in Firefox 154 Internally found bugs fixed in Thunderbird 154

Mon, 24 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Title Internally found bugs fixed in Thunderbird 154 Internally found bugs fixed in Firefox 154

Fri, 21 Aug 2026 12:15:00 +0000


Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154. Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Title Internally found bugs fixed in Firefox 154 Internally found bugs fixed in Thunderbird 154
References

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154.
Title Internally found bugs fixed in Firefox 154
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:25:17.482Z

Reserved: 2026-08-17T11:59:23.603Z

Link: CVE-2026-74989

cve-icon Vulnrichment

Updated: 2026-08-20T15:51:25.444Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T13:17:40.810

Modified: 2026-09-01T22:17:12.353

Link: CVE-2026-74989

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:41Z

Links: CVE-2026-74989 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T06:45:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-825

    Expired Pointer Dereference