CVE-2026-57963
published 2026-07-01CVE-2026-57963: An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.18%
7.8th percentile
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | thunderbird | < Thunderbird 152.0.1 | Thunderbird 152.0.1 |
| mozilla | thunderbird | < Thunderbird 140.12.1 | Thunderbird 140.12.1 |
| mozilla | thunderbird | < 140.12.1 | 140.12.1 |
| mozilla | thunderbird | < 152.0.1 | 152.0.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI.
ghsa_unreviewed·2026-07-01
CVE-2026-57963 [MEDIUM] CWE-79 An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI.
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
Mozilla
Mozilla Foundation Security Advisory 2026-63: CVE-2026-57963
vendor_mozilla·CVSS 6.5
CVE-2026-57963 [MEDIUM] Mozilla Foundation Security Advisory 2026-63: CVE-2026-57963
Mozilla Foundation Security Advisory 2026-63
CVE: CVE-2026-57963
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152.0.1
Mozilla
Mozilla Foundation Security Advisory 2026-64: CVE-2026-57963
vendor_mozilla·CVSS 6.5
CVE-2026-57963 [MEDIUM] Mozilla Foundation Security Advisory 2026-64: CVE-2026-57963
Mozilla Foundation Security Advisory 2026-64
CVE: CVE-2026-57963
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.12.1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-01
Published