EXPOSURES › CVE-2026-84143
CVE-2026-84143
CRITICALMozilla Thunderbird 154 and earlier versions contained internally found memory corruption bugs that could have been exploited.
Mozilla discovered memory corruption vulnerabilities in Thunderbird 154, ESR 153.1, and ESR 140.14 before public disclosure, which could have allowed remote code execution. DIB organizations must ensure their email clients are patched to the latest versions to prevent potential exploitation of these internal bugs.
Shame score — Internally found bugs with memory corruption defects that could have been exploited indicate avoidable negligence in patching and internal vulnerability management.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.