SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-84637

CRITICAL · CVSS 9.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-07

CyberRota Analysis

AI-Generated

Malicious calendar invitations in Windows can exploit file URI attachments to execute local or network-hosted executables, circumventing Thunderbird's standard protections against executable attachments. This vulnerability poses a significant risk as it allows attackers to mislead users with deceptive filenames, potentially leading to unauthorized code execution. Organizations using Thunderbird, particularly those with a reliance on calendar functionalities, should prioritize applying the latest updates to mitigate this risk.

CVE
CVE-2026-84637
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%
Windows

Original NVD Description

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)