CVE-2026-92239: Mozilla Thunderbird

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Thunderbird: before 140.16.0 (fixed in 140.16.0); from 141.0, before 153.3.0 (fixed in 153.3.0); from 154.0, before 156.0 (fixed in 156.0)

Published 2026-09-15. Last modified 2026-09-24.