SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-84640

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-07

CyberRota Analysis

AI-Generated

A vulnerability exists in certain versions of Thunderbird where a specially crafted mail header can cause a one-byte read past the end of a buffer, potentially leading to information disclosure or application instability. Users of affected Thunderbird versions should prioritize updating to Thunderbird 155, 140.15, or 153.2 to mitigate this risk. Organizations relying on Thunderbird for email communication should assess their deployments and ensure they are running the patched versions.

CVE
CVE-2026-84640
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)