Description
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The report describes several internal bugs affecting Thunderbird 154 that manifest as memory corruption or other security‑relevant defects. These weaknesses, associated with CWE‑119 and CWE‑200, could allow an attacker to compromise the application process or alter sensitive data in memory if the vulnerable code path can be successfully triggered.

Affected Systems

Mozilla Thunderbird 154 and Mozilla Firefox 154 are affected. The vulnerabilities were addressed in Thunderbird 155 and Firefox 155. Any installation of the affected versions, either standalone or bundled with other Mozilla releases, remains vulnerable until updated.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The flaw is not listed in CISA’s KEV catalog, implying no publicly known active exploits. The exact attack vector is not specified; however, based on the memory corruption nature and the application context, it is reasonable to infer that the flaw could be triggered by a maliciously crafted email, attachment, or message that a user opens, potentially requiring local user interaction. If the vulnerable code processes external network data, remote exploitation could also be conceivable. An attacker who succeeds would obtain full control of the Thunderbird or Firefox process.

Generated by OpenCVE AI on September 3, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Thunderbird to version 155 or later
  • Upgrade Mozilla Firefox to version 155 or later
  • Implement email filtering or sandboxing to limit the exposure of potential malicious attachments until a patch is applied

Generated by OpenCVE AI on September 3, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-787

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
Weaknesses CWE-119
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 02 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-787

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155. Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Title Internally found bugs fixed in Firefox 155 Internally found bugs fixed in Thunderbird 155
References

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155.
Title Internally found bugs fixed in Firefox 155
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T17:23:40.751Z

Reserved: 2026-09-01T07:26:00.760Z

Link: CVE-2026-84142

cve-icon Vulnrichment

Updated: 2026-09-03T17:13:49.305Z

cve-icon NVD

Status : Modified

Published: 2026-09-01T13:20:08.337

Modified: 2026-09-03T18:17:26.900

Link: CVE-2026-84142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T21:45:09Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor