
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84640 is a one-byte out-of-bounds read vulnerability in Mozilla Thunderbird's mail parser, described as "One byte overflow read in mail parser." A maliciously constructed mail header can trigger a one-byte read past the end of a buffer during mail header processing. The vulnerability affects Mozilla Thunderbird prior to versions 155, 140.15 (ESR), and 153.2 (ESR), and was disclosed on September 1, 2026. It was reported by Ramesh Adhikari and Dr. Faruk Kazi of CoE-CNDS Lab, VJTI, Mumbai, India. Mozilla rates the impact as medium (Mozilla MFSA2026-86, Mozilla MFSA2026-87, Mozilla MFSA2026-88).
The root cause is an off-by-one buffer over-read (CWE-125) in Thunderbird's mail header parsing logic. When processing a specially crafted mail header, the parser reads one byte beyond the allocated buffer boundary, constituting a memory disclosure condition. The attack vector is network-based and requires no authentication — an attacker simply sends a crafted email to a target Thunderbird user. Mozilla notes that in general these flaws cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but they may present risks in browser or browser-like contexts (Mozilla MFSA2026-86, Mozilla MFSA2026-87).
Successful exploitation allows an unauthenticated attacker to read one byte of memory beyond the intended buffer boundary, resulting in a limited memory disclosure. The primary impact is on confidentiality; integrity and availability are not directly affected by this vulnerability. While the single-byte read limits the scope of data exposure, such out-of-bounds reads can in some contexts leak sensitive in-memory data or contribute to information leakage that aids further exploitation (Mozilla MFSA2026-86, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). The EPSS score is reported as 0.0, indicating very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Mozilla has released patches addressing CVE-2026-84640 in the following versions: Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2, all announced September 1, 2026. Users should update to one of these patched releases as soon as possible. No configuration-based workarounds have been published; upgrading is the recommended and only confirmed remediation (Mozilla MFSA2026-86, Mozilla MFSA2026-87, Mozilla MFSA2026-88).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."