Mozilla Thunderbird: 25 Vulnerabilities Disclosed, Including Critical Sandbox Escapes
Key findings • 25 vulnerabilities disclosed for Mozilla Thunderbird between Sept 29-30, 2026. • Critical sandbox escape flaws (CVE-2026-100819, CVE-2026-100811) and high-severity use-after-fr…

Key findings
- 25 vulnerabilities disclosed for Mozilla Thunderbird between Sept 29-30, 2026.
- Critical sandbox escape flaws (CVE-2026-100819, CVE-2026-100811) and high-severity use-after-free bugs reported.
- Vulnerabilities impact memory corruption, privilege escalation, and information disclosure.
- Patched in Thunderbird 157, 153.4, and 140.17; users urged to update.
- Heap buffer overflow possible with emails >= 2GB (CVE-2026-103500).
On September 29-30, 2026, a significant batch of 25 vulnerabilities was disclosed for Mozilla Thunderbird, impacting various components of the email client. These vulnerabilities range in severity from medium to critical, with several critical sandbox escape flaws and high-severity use-after-free and privilege escalation issues. The disclosure highlights potential risks to user data and system integrity if not promptly addressed.
Several vulnerabilities fall into the category of memory corruption, including use-after-free bugs in the Graphics: Canvas2D component (CVE-2026-100832), DOM: UI Events & Focus Handling (CVE-2026-100831), the JavaScript Engine: JIT (CVE-2026-100825, CVE-2026-100814, CVE-2026-100813), CSS Parsing and Computation (CVE-2026-100815), and the Widget: Gtk component (CVE-2026-100818). Additionally, a critical sandbox escape due to incorrect boundary conditions in the XPCOM component (CVE-2026-100819) and another sandbox escape due to use-after-free in the DOM: Core & HTML component (CVE-2026-100811) were reported.
Other notable vulnerabilities include privilege escalation flaws in the Places component (CVE-2026-100824) and the Address Bar component (CVE-2026-100820). A heap buffer overflow (CVE-2026-100800) could occur if a user opens an email exceeding 2GB. Information disclosure in the Networking component (CVE-2026-96869) and spoofing issues in the Networking: HTTP component (CVE-2026-100822) also present risks. Several mitigation bypasses were identified across different components, including DOM: Navigation (CVE-2026-100830), DOM: Security (CVE-2026-100829), Bookmarks & History (CVE-2026-100828), and DOM: Service Workers (CVE-2026-100808). Denial-of-service vulnerabilities were found in the Storage: StorageManager component (CVE-2026-100826) and the Graphics component (CVE-2026-100812).
The majority of these vulnerabilities were fixed in Thunderbird versions 157, 153.4, and 140.17. Users are strongly advised to update to the latest available version to protect themselves from these security risks. The broad range of vulnerabilities and their severity underscore the importance of timely patching for email clients, which often serve as a primary vector for sophisticated attacks.
This batch of disclosures, affecting both Thunderbird and Firefox, indicates a coordinated effort to address a wide array of security weaknesses across Mozilla's product ecosystem. Users should ensure their Thunderbird installations are up-to-date, as these patches are crucial for maintaining the security and integrity of their email communications and personal data.
The vulnerabilities patched include: CVE-2026-103500, CVE-2026-96869, CVE-2026-100832, CVE-2026-100831, CVE-2026-100830, CVE-2026-100829, CVE-2026-100828, CVE-2026-100826, CVE-2026-100825, CVE-2026-100824, CVE-2026-100822, CVE-2026-100821, CVE-2026-100820, CVE-2026-100819, CVE-2026-100818, CVE-2026-100817, CVE-2026-100816, CVE-2026-100815, CVE-2026-100814, CVE-2026-100813, CVE-2026-100812, CVE-2026-100811, CVE-2026-100810, CVE-2026-100809, CVE-2026-100808.