CVE-2026-84637
Mozilla · Thunderbird
A vulnerability in Mozilla Thunderbird allows unauthenticated attackers to execute local or network-hosted files via malicious calendar invitations, bypassing attachment security protections on Windows.
Executive summary
A critical remote code execution vulnerability in Mozilla Thunderbird allows unauthenticated attackers to execute malicious files through crafted calendar invitations, posing a severe risk to Windows users.
Vulnerability
The flaw exists in the calendar invitation display mechanism, which fails to properly validate file URI attachments. An unauthenticated attacker can leverage this to bypass executable attachment protections on Windows, potentially leading to unauthorized code execution.
Business impact
The potential for unauthenticated remote code execution makes this a critical security threat, as evidenced by the high CVSS score of 9.8. Successful exploitation could lead to full system compromise, including the theft of sensitive data, installation of malware, or complete loss of workstation integrity. Organizations relying on Thunderbird for email and calendar management face significant operational and data security risks if this vulnerability is not addressed.
Remediation
Immediate Action: Update Mozilla Thunderbird to version 153.2, 154, or any later release to apply the necessary security patches.
Proactive Monitoring: Review endpoint security logs for unusual process spawning activities originating from the Thunderbird application or unexpected network connections triggered by calendar invitations.
Compensating Controls: Implement organizational policies to restrict the execution of untrusted attachments and utilize endpoint detection and response (EDR) tools to block suspicious child processes initiated by email clients.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for full system compromise, immediate patching is required. All systems running Mozilla Thunderbird should be updated to the latest version as a priority to mitigate the risk of remote code execution. Security teams should ensure that all endpoints are compliant and monitor for any suspicious activity related to calendar invitation processing.
More Mozilla CVEs
Sources
Originally found and disclosed by Trung Nguyen, per the CVE Program record.