CVE-2026-92238EPSS p43.4%
CVE-2026-92238CVE-2026-92238
mozilla / thunderbird
Description
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.54% probability of exploitation · percentile 43.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |