CVE-2025-26696: Mozilla Thunderbird
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
Affected products
- Mozilla Thunderbird: before 128.8.0 (fixed in 128.8.0); from 129.0, before 136.0 (fixed in 136.0)
Published 2025-03-10. Last modified 2026-06-17.