CVE-2026-84144
published 2026-09-01CVE-2026-84144: Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another…
PriorityP341high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.24%
15.4th percentile
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 155 | Firefox 155 |
| mozilla | firefox | < 153.2.0 | 153.2.0 |
| mozilla | firefox | >= 154.0.0 < 155.0.0 | 155.0.0 |
| mozilla | firefox_esr | < Firefox ESR 153.2 | Firefox ESR 153.2 |
| mozilla | thunderbird | < Thunderbird 155 | Thunderbird 155 |
| mozilla | thunderbird | < Thunderbird 153.2 | Thunderbird 153.2 |
| mozilla | thunderbird | < 153.2.0 | 153.2.0 |
| mozilla | thunderbird | >= 154.0 < 155.0 | 155.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Mozilla
Mozilla Foundation Security Advisory 2026-86: CVE-2026-84144
vendor_mozilla
CVE-2026-84144 Mozilla Foundation Security Advisory 2026-86: CVE-2026-84144
Mozilla Foundation Security Advisory 2026-86
CVE: CVE-2026-84144
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 155
Mozilla
Mozilla Foundation Security Advisory 2026-85: CVE-2026-84144
vendor_mozilla
CVE-2026-84144 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84144
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84144
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
Mozilla
Mozilla Foundation Security Advisory 2026-88: CVE-2026-84144
vendor_mozilla
CVE-2026-84144 Mozilla Foundation Security Advisory 2026-88: CVE-2026-84144
Mozilla Foundation Security Advisory 2026-88
CVE: CVE-2026-84144
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 153.2
Mozilla
Mozilla Foundation Security Advisory 2026-82: CVE-2026-84144
vendor_mozilla
CVE-2026-84144 Mozilla Foundation Security Advisory 2026-82: CVE-2026-84144
Mozilla Foundation Security Advisory 2026-82
CVE: CVE-2026-84144
Product: Firefox
Impact: high
Fixed in: Firefox 155
VulDB
Mozilla Firefox 153.1/154 memory corruption (Nessus ID 342304)
vuldb·2026-09-03
CVE-2026-84144 [CRITICAL] Mozilla Firefox 153.1/154 memory corruption (Nessus ID 342304)
A vulnerability, which was classified as critical, was found in Mozilla Firefox 153.1/154. Affected is an unknown function. Such manipulation leads to memory corruption.
This vulnerability is documented as CVE-2026-84144. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
Internally found bugs present in Firefox 154 and Firefox ESR 153.1.
ghsa_unreviewed·2026-09-01
CVE-2026-84144 Internally found bugs present in Firefox 154 and Firefox ESR 153.1.
Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054619%2C2054620%2C2054624%2C2054702%2C2054726%2C2054775%2C2055703%2C2058006%2C2058013%2C2058098%2C2058627%2C2058661%2C2059127%2C2059128%2C2059180%2C2059199%2C2059205%2C2061320%2C2061430%2C2061495%2C2061505%2C2061532%2C2061799https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054625%2C2059002%2C2061775https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054691%2C2058085%2C2059144%2C2059191%2C2059192%2C2061521%2C2062395%2C2062404https://www.mozilla.org/security/advisories/mfsa2026-82/https://www.mozilla.org/security/advisories/mfsa2026-85/https://www.mozilla.org/security/advisories/mfsa2026-86/https://www.mozilla.org/security/advisories/mfsa2026-88/
2026-09-01
Published