BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Thunderbird 156 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-92035Sandbox escape due to incorrect boundary conditions in the Graphics component
- CVE-2026-92238Ambiguous parsing of mail headers
- CVE-2026-92072Incorrect boundary conditions in the Safe Browsing component
- CVE-2026-92074Mitigation bypass in the Popup Blocker component
- CVE-2026-92075Mitigation bypass in the Networking component
- CVE-2026-92076Incorrect boundary conditions in the Networking component
- CVE-2026-92079Mitigation bypass in the Widget: Win32 component
- CVE-2026-92240Out-of-bounds read in IMAP response parser
- CVE-2026-92239Buffer overrun in IMAP
- CVE-2026-92068Site isolation issue in the Reader Mode component
- CVE-2026-92069Spoofing issue in the DOM: Navigation component
- CVE-2026-92070Information disclosure in the Networking component
- CVE-2026-92071Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
- CVE-2026-92066Sandbox escape in the Profile Backup component
- CVE-2026-92065Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
- CVE-2026-92064Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
- CVE-2026-92061Incorrect boundary conditions in the Security: Process Sandboxing component
- CVE-2026-92059Incorrect boundary conditions in the DOM: Editor component
- CVE-2026-92057Mitigation bypass in the Enterprise Policies component
- CVE-2026-92051Spoofing issue due to invalid pointer in the Graphics component
- CVE-2026-92050Sandbox escape due to race condition in the XPConnect component
- CVE-2026-92048Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
- CVE-2026-92045Sandbox escape due to incorrect boundary conditions in the WebRTC component
- CVE-2026-92044Information disclosure in the Networking: HTTP component
- CVE-2026-92041Mitigation bypass in the DOM: Networking component
- CVE-2026-92039Mitigation bypass in the DOM: Notifications component
- CVE-2026-92038Mitigation bypass in the Remote Settings Client component
- CVE-2026-92037Incorrect boundary conditions in the DOM: Animation component
- CVE-2026-92036Incorrect boundary conditions in the Networking: HTTP component
- CVE-2026-92034Site isolation issue in the Graphics component
- CVE-2026-92032Sandbox escape due to invalid pointer in the Graphics component
- CVE-2026-92031Information disclosure in the Graphics: ImageLib component
- CVE-2026-92030Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
- CVE-2026-92019Mitigation bypass in the Remote Settings Client component
- CVE-2026-92016Use-after-free in the Disability Access APIs component
- CVE-2026-92042Race condition in the DOM: Content Processes component
- CVE-2026-92063Denial-of-service in the Audio/Video component
- CVE-2026-92077Denial-of-service in the SVG component
- CVE-2026-92078Denial-of-service in the Security component
- CVE-2026-92067Use-after-free in the Widget: Gtk component
- CVE-2026-92060Use-after-free in the Internationalization component
- CVE-2026-92056Use-after-free in the Graphics: Text component
- CVE-2026-92049Use-after-free in the Widget: Win32 component
- CVE-2026-92058Use-after-free in the Graphics component
- CVE-2026-92046Use-after-free in the Graphics component
- CVE-2026-92040Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-92029Use-after-free in the SVG component
- CVE-2026-92028Use-after-free in the DOM: Core & HTML component
- CVE-2026-92024Use-after-free in the SVG component
- CVE-2026-92023Use-after-free in the XML component
Source and provenance
Original title: Security Vulnerabilities fixed in Thunderbird 156 — Mozilla. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗