SEPTEMBER 24, 2026
Live Feed
Back to database
Case File

CVE-2026-92238

CRITICAL · CVSS 9.8 EPSS 0.61%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-24

CyberRota Analysis

AI-Generated

A vulnerability exists in certain versions of Thunderbird where a specially crafted mail header may cause multiple fields to be incorrectly parsed as a single entity, potentially leading to memory safety violations. This could allow an attacker to exploit the issue to execute arbitrary code or disrupt service. Organizations using affected versions of Thunderbird should prioritize updating to version 156 or 140.16 to mitigate the risk.

CVE
CVE-2026-92238
Severity
CRITICAL
CVSS
9.8
EPSS
0.61%

Original NVD Description

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)