Spoofing Vulnerability in Thunderbird by Mozilla
CVE-2026-3889
6.5MEDIUM
What is CVE-2026-3889?
A spoofing vulnerability exists in Thunderbird, which could allow attackers to impersonate legitimate users in email communications. This issue impacts Thunderbird versions earlier than 149 and 140.9, potentially leading to misleading information being sent or received in emails. Users are encouraged to upgrade to the latest versions to mitigate the risk.
Affected Version(s)
Thunderbird < 149
Thunderbird < 140.9