Security Vulnerability in Mozilla Thunderbird Email Client
CVE-2026-84637

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84637?

A vulnerability in Mozilla Thunderbird allows attackers to exploit calendar invitations with file URI attachments, potentially executing local or network-hosted executables without proper protections. This occurs particularly when the new invitation display is enabled, which can misleadingly show the attachment with a deceptive filename. Fixes were implemented in Thunderbird versions 154 and 153.2 to address this security flaw.

Affected Version(s)

Thunderbird 153.2

Thunderbird 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trung Nguyen
.