SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-84641

HIGH · CVSS 7.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-07

CyberRota Analysis

AI-Generated

A vulnerability exists in unspecified versions of Thunderbird, where a malicious IMAP server can exploit a crafted ID response to trigger a use-after-free condition and disclose heap memory contents, potentially leading to sensitive information being written to prefs.js. Organizations using affected versions of Thunderbird should prioritize updating to versions 155, 140.15, or 153.2 to mitigate the risk of information exposure. This issue is particularly relevant for environments that rely on email communications and may be targeted by attackers leveraging IMAP.

CVE
CVE-2026-84641
Severity
HIGH
CVSS
7.5
EPSS
0.27%

Original NVD Description

A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)