BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Thunderbird 140.14 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 02:00 UTC
Linked CVEs31
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-74983Mitigation bypass in the Data Loss Prevention component
- CVE-2026-74990Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- CVE-2026-74987Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- CVE-2026-74949Privilege escalation due to use-after-free in the Graphics: Canvas2D component
- CVE-2026-74944Use-after-free in the DOM: Core & HTML component
- CVE-2026-74943Use-after-free in the Graphics: ImageLib component
- CVE-2026-74940Use-after-free in the Graphics: Text component
- CVE-2026-74936Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-74934Site isolation issue in the Graphics: CanvasWebGL component
- CVE-2026-74948Information disclosure in the Graphics component
- CVE-2026-74957Mitigation bypass in the Safe Browsing component
- CVE-2026-74959Mitigation bypass in the Storage: Cache API component
- CVE-2026-74960Site isolation issue in the WebExtensions component
- CVE-2026-74945Information disclosure in the Graphics: Text component
- CVE-2026-74935Privilege escalation in the DOM: Networking component
- CVE-2026-74939Privilege escalation in the DOM: Navigation component
- CVE-2026-74941Privilege escalation in the Graphics: CanvasWebGL component
- CVE-2026-74942Privilege escalation in the Remote Settings Client component
- CVE-2026-74946Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- CVE-2026-74953Privilege escalation in the Networking: Cookies component
- CVE-2026-74965Privilege escalation in the Shell Integration component
- CVE-2026-74969Use-after-free in the Layout: Text and Fonts component
- CVE-2026-74976JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-74964Integer overflow in the Graphics component
- CVE-2026-74962Site isolation issue in the Networking: Cookies component
- CVE-2026-74974Same-origin policy bypass in the Graphics: ImageLib component
- CVE-2026-74967Same-origin policy bypass in the Audio/Video: Playback component
- CVE-2026-74963Same-origin policy bypass in the Networking: Cookies component
- CVE-2026-74972Information disclosure in the DOM: Push Subscriptions component
- CVE-2026-74971Information disclosure in the DOM: UI Events & Focus Handling component
- CVE-2026-74973Race condition, use-after-free in the Graphics component
Source and provenance
Original title: Security Vulnerabilities fixed in Thunderbird 140.14 — Mozilla. Captured 27 Sept 2026, 02:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗