EXPOSURES › CVE-2026-84142
CVE-2026-84142
CRITICALMozilla Thunderbird 154 contained internally found memory corruption bugs that could have been exploited, fixed in version 155.
Thunderbird 154 shipped with memory corruption vulnerabilities that Mozilla identified internally before public disclosure. DIBs must ensure Thunderbird is patched to 155 or later to prevent potential exploitation of these defects. The failure highlights the risk of shipping software with known, unpatched security flaws.
Shame score — Shipping software with known, internally found memory corruption bugs that could have been exploited demonstrates negligence in the release cycle.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.