A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92238
NONE
EPSS 0.18%
Updated Sep 16, 2026
Thunderbird
https://bugzilla.mozilla.org/show_bug.cgi?id=2060601
security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-94/
security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-95/
security@mozilla.org
https://www.mozilla.org/security/advisories/mfsa2026-96/
security@mozilla.org
CVE Details
CVE ID
CVE-2026-92238
Published Date
Sep 15, 2026
Vendor
Thunderbird
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
7.7th percentile (higher than 7.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory