cbcvebase.
CVE-2026-57963
published 2026-07-01

CVE-2026-57963: An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI…

PriorityP336medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.18%
7.8th percentile
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.

Affected

4 ranges
VendorProductVersion rangeFixed in
mozillathunderbird< Thunderbird 152.0.1Thunderbird 152.0.1
mozillathunderbird< Thunderbird 140.12.1Thunderbird 140.12.1
mozillathunderbird< 140.12.1140.12.1
mozillathunderbird< 152.0.1152.0.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.