Description
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Published: 2026-09-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption with potential for arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Internally discovered bugs in Thunderbird 154 and Thunderbird ESR 153.1 caused memory corruption or other security‑relevant defects. These defects fall under the memory‑corruption weakness represented by CWE-119, and could allow an attacker with sufficient effort to execute arbitrary code within the Thunderbird process, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

Thunderbird 154 and Thunderbird ESR 153.1 are affected. The same bugs were fixed in Firefox 155 and Firefox ESR 153.2, indicating that earlier releases of Firefox—those older than 155 or ESR 153.2—are likely vulnerable as well. Systems running these older Thunderbird or Firefox releases remain at risk until updated to the fixed versions.

Risk and Exploitability

The CVSS score of 7.5 and an EPSS score of <1% suggest a moderate severity with a currently low known exploitation probability. The vulnerability is not listed in CISA KEV. Based on typical exploitation methods for memory corruption in email clients, the likely attack vector is delivery of malicious email content or web material that triggers the underlying bug. An attacker would need to devise content designed to exploit the memory corruption; no public exploitation has been observed yet, but the theoretical risk remains.

Generated by OpenCVE AI on September 3, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Thunderbird to version 155 or Thunderbird ESR 153.2 or later
  • Upgrade Firefox to version 155 or Firefox ESR 153.2 or later
  • Enable automatic updates in both Thunderbird and Firefox to receive future security patches promptly
  • Review installed add‑ons and extensions for both clients and remove any that are no longer needed or come from untrusted sources

Generated by OpenCVE AI on September 3, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 03 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 02 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-416

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Title Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2
References

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-416

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T15:41:26.571Z

Reserved: 2026-09-01T07:26:01.858Z

Link: CVE-2026-84144

cve-icon Vulnrichment

Updated: 2026-09-03T15:41:15.829Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T13:20:08.563

Modified: 2026-09-03T16:33:15.953

Link: CVE-2026-84144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T21:30:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer