VDB

ESB-2026.5399

ESB-2026.5399 PUBLISHED CVSS 9.800000190734863 CRITICAL

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.5399 MFSA 2026-51 Security Vulnerabilities fixed in Thunderbird 140.11 20 May 2026 =========================================================================== AUSCERT Security Bulletin Summary --------------------------------- Product: Mozilla Thunderbird Publisher: Mozilla Foundation Operating System: Windows Linux macOS Resolution: Patch/Upgrade CVE Names: CVE-2026-8391 CVE-2026-8401 CVE-2026-8946 CVE-2026-8947 CVE-2026-8949 CVE-2026-8950 CVE-2026-8953 CVE-2026-8954 CVE-2026-8955 CVE-2026-8956 CVE-2026-8957 CVE-2026-8958 CVE-2026-8959 CVE-2026-8961 CVE-2026-8962 CVE-2026-8968 CVE-2026-8970 CVE-2026-8974 CVE-2026-8975 CVE-2026-8388 Original Bulletin: https://www.mozilla.org/en-US/security/advisories/mfsa2026-51/ Comment: CVSS (Max): 9.8 CVE-2026-8975 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVSS Source: [CISA-ADP], SUSE Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H EPSS (Max): 0.1% (26th)* CVE-2026-8391 2026-05-19 * Not all EPSS found when published - --------------------------BEGIN INCLUDED TEXT-------------------- Mozilla Foundation Security Advisory 2026-51 Security Vulnerabilities fixed in Thunderbird 140.11 Announced: May 19, 2026 Impact: high Products: Thunderbird Fixed in: Thunderbird 140.11 In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. # CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component Reporter: zx Impact: high References o Bug 2029070 # CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component Reporter: ggwhyp Impact: high References o Bug 2036978 # CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component Reporter: Satoki Tsuji Impact: high References o Bug 2038439 # CVE-2026-8391: Other issue in the JavaScript Engine component Reporter: ggwhyp Impact: high References o Bug 2038575 # CVE-2026-8401: Sandbox escape in the Profile Backup component Reporter: ggwhyp Impact: high References o Bug 2038679 # CVE-2026-8949: Integer overflow in the Widget: Win32 component Reporter: q1 Impact: moderate References o Bug 1355639 # CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component Reporter: Jakub Szymsza Impact: moderate References o Bug 1965430 # CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component Reporter: stevej Impact: moderate References o Bug 2029511 # CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/ Video component Reporter: Ameen Basha M K Impact: moderate References o Bug 2030747 # CVE-2026-8955: Privilege escalation in the DOM: Workers component Reporter: lebr0nli Impact: moderate References o Bug 2031064 # CVE-2026-8956: Integer overflow in the Networking: JAR component Reporter: Yaqoub Aldurayhim Impact: moderate References o Bug 2032427 # CVE-2026-8957: Privilege escalation in the Enterprise Policies component Reporter: Mateusz Dobrzynski Impact: moderate References o Bug 2033850 # CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component Reporter: Yaqoub Aldurayhim Impact: moderate References o Bug 2034713 # CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component Reporter: Ameen Basha M K Impact: moderate References o Bug 2034754 # CVE-2026-8961: Spoofing issue in the Form Autofill component Reporter: Hafiizh Impact: low References o Bug 1962625 # CVE-2026-8962: Mitigation bypass in the DOM: Security component Reporter: Manojkumar Jaganathan Impact: low References o Bug 2004804 # CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component Reporter: Tristan Madani Impact: low References o Bug 2030467 # CVE-2026-8970: Privilege escalation in the Security component Reporter: pakhunov.anton.n Impact: low References o Bug 2032174 # CVE-2026-8974: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 Reporter: Nika Layzell, Randell Jesup, Timothy Nikkel, Tom Schuster and the Mozilla Fuzzing Team Impact: moderate Description Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References o Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 # CVE-2026-8975: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 Reporter: Andrew McCreight, Valentin Gosu, Nika Layzell, Tom Schuster and the Mozilla Fuzzing Team Impact: high Description Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References o Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 - --------------------------END INCLUDED TEXT---------------------- You have received this e-mail bulletin as a result of your organisation's registration with AUSCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AUSCERT's members. As AUSCERT did not write the document quoted above, AUSCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AUSCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://portal.auscert.org.au/bulletins/ =========================================================================== AUSCERT The University of Queensland, Brisbane QLD 4072 Australia e: auscert@auscert.org.au t: +61 (0)7 3365 4417 Allies in Cyber Security ===========================================================================

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Mozilla FoundationMozilla Thunderbird

Timeline

  • May 19, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›