Thunderbird Esr
260 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Thunderbird Esr, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Thunderbird Esr CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 6 |
| 2025-02 | 8 |
| 2025-03 | 10 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 4 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 260 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical148
- High30
- Medium81
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Thunderbird Esr.
- CVE-2026-6786Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 1507.5
- CVE-2026-6785Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 1507.5
- CVE-2026-5734Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.29.8
- CVE-2026-5731Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.29.8
- CVE-2026-0891Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 1478.1
- CVE-2025-3523User Interface (UI) Misrepresentation of attachment URL6.4
- CVE-2025-3522Leak of hashed Window credentials via crafted attachment URL6.3
- CVE-2025-2830Information Disclosure of /tmp directory listing6.3
- CVE-2025-26696Crafted email message incorrectly shown as being encrypted7.0
- CVE-2025-26695Downloading of OpenPGP keys from WKD used incorrect padding5.3
- CVE-2025-1938Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.86.5
- CVE-2025-1936Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents7.3
- CVE-2025-1937Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.87.5
- CVE-2025-1935Clickjacking the registerProtocolHandler info-bar4.3
- CVE-2025-1934Unexpected GC during RegExp bailout processing6.5
Product grouping is registry-driven, with AI assist and human review. How it works