CVE-2026-5731
CVE-2026-5732
CVE-2026-5734
These vulnerabilities may allow remote code execution, meaning an attacker could potentially run malicious code on a victim’s system by sending specially crafted emails.
All major platforms are impacted since they share the same core codebase developed by Mozilla:
Windows
Linux
macOS
The issues have been resolved in:
Thunderbird 140.9.1 ESR (and newer)
The vulnerabilities are related to common high-risk areas such as:
Memory corruption
Use-after-free bugs
Improper handling of email content (HTML/MIME)
This makes them particularly dangerous, as exploitation can occur via email content without direct user interaction.
Update Thunderbird immediately
Ensure automatic updates are enabled
Avoid using outdated versions
Windows:
Go to Help → About Thunderbird
The client will automatically check for updates
Linux:
Update via your system’s package manager or use the official Mozilla build