Mozilla Thunderbird ↗
Summary iPlain-English security verdict for Mozilla Thunderbird, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.
Mozilla Thunderbird currently scores 5/100 — critical, with active exploitation. 3 of its known vulnerabilities are being actively exploited in the wild (CISA KEV), including CVE-2024-9680. Upgrade immediately and review your exposure to the actively-exploited CVEs below.
Disclosure trend iNew CVEs published for Mozilla Thunderbird each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.
1 of its known vulnerability is linked to ransomware campaigns (CISA KEV).
Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.
Most urgent first — actively exploited, then likeliest to be exploited.
CVE-2024-9680 CRITICAL exploited ransomware Use-after-free EPSS 23% → fixed in 128.3.1 CVE-2022-26485 HIGH exploited Use-after-free EPSS 14% → fixed in 91.6.2 CVE-2022-26486 CRITICAL exploited Use-after-free EPSS 2% → fixed in 91.6.2 CVE-2026-4689 CRITICAL Integer overflow EPSS 1% → fixed in 149.0 CVE-2026-2796 CRITICAL CWE-843 EPSS 1% → fixed in 148.0 CVE-2026-74943 CRITICAL Use-after-free EPSS 1% → fixed in 153.1.0 CVE-2026-2773 CRITICAL Memory corruption EPSS 1% → fixed in 148.0 CVE-2026-2775 CRITICAL CWE-288 EPSS 1% → fixed in 148.0 CVE-2026-2762 CRITICAL Integer overflow EPSS 1% → fixed in 148.0 CVE-2026-2774 CRITICAL Integer overflow EPSS 1% → fixed in 148.0 CVE-2026-74990 CRITICAL Memory corruption EPSS 1% → fixed in 153.1.0 CVE-2026-0879 CRITICAL Memory corruption EPSS 1% → fixed in 147.0See all 267 known Mozilla Thunderbird CVEs & security history →
Get alerted about Mozilla Thunderbird
Be emailed the moment Mozilla Thunderbird gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.
We email only on real events for Mozilla Thunderbird — no marketing, no sharing, and we never know what you run. Track your whole stack →
Frequently asked
Is Mozilla Thunderbird safe and patched?
Mozilla Thunderbird currently scores 5/100 — critical, with active exploitation. 3 of its known vulnerabilities are being actively exploited in the wild (CISA KEV), including CVE-2024-9680. Upgrade immediately and review your exposure to the actively-exploited CVEs below.
What should I do about Mozilla Thunderbird now?
Review the patch-priority list, apply the available fixes (or move to the latest release), and confirm against Mozilla's official advisory. Some issues are under active exploitation, so treat this as urgent.
lifecycle unknown — needs latest supported version
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Mozilla's official advisory before you patch or upgrade — Mozilla Thunderbird official site ↗