SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-84639

CRITICAL · CVSS 9.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-07

CyberRota Analysis

AI-Generated

Certain versions of Thunderbird are vulnerable due to an error condition in specific MIME bodies that can lead to the use of uninitialized memory. This could potentially allow an attacker to exploit the vulnerability, leading to unpredictable behavior or information disclosure. Organizations using affected Thunderbird versions should prioritize updating to the fixed releases to mitigate potential risks.

CVE
CVE-2026-84639
Severity
CRITICAL
CVSS
9.1
EPSS
0.32%

Original NVD Description

Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)