
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84641 is an information disclosure vulnerability in Mozilla Thunderbird caused by a use-after-free condition triggered by a malicious IMAP server response. When Thunderbird connects to a rogue IMAP server, the server can send a crafted ID response that causes heap-memory contents to be disclosed and potentially persisted to the user's prefs.js file. The vulnerability was disclosed on September 1, 2026, and affects Thunderbird versions prior to 155, 140.15 (ESR), and 153.2 (ESR). It is rated low impact by Mozilla and estimated as Medium severity by Feedly; an official CVSS score had not been published at time of writing (Mozilla Advisory MFSA2026-86, Mozilla Advisory MFSA2026-87, Mozilla Advisory MFSA2026-88).
The root cause is classified as CWE-825 (Expired Pointer Dereference), manifesting as a use-after-free when Thunderbird processes a crafted IMAP ID command response from a server it is connected to. The freed heap memory is subsequently read and its contents can be written to the user's prefs.js preferences file, enabling persistent exfiltration of sensitive heap data. Exploitation requires the victim's Thunderbird client to connect to an attacker-controlled or compromised IMAP server — either by tricking the user into configuring a malicious account or by performing a man-in-the-middle attack on an existing IMAP connection. The bug was reported by researcher ABDULAZIZ ALASAIQAH and tracked internally as Mozilla Bug 2057805 (Mozilla Advisory MFSA2026-86, Red Hat Bugzilla).
Successful exploitation results in disclosure of heap memory contents from the Thunderbird process, which may include sensitive data such as credentials, session tokens, or other in-memory secrets. These heap contents can be persisted to the prefs.js file on disk, potentially allowing an attacker with subsequent file-system access to retrieve the disclosed data. The vulnerability does not directly enable remote code execution or privilege escalation, and its impact is limited to confidentiality (Mozilla Advisory MFSA2026-86, Mozilla Advisory MFSA2026-88).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-84641 as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to control or impersonate an IMAP server that the victim connects to, raising the bar for opportunistic attacks (Feedly, Red Hat Bugzilla).
ID command response.ID response that triggers a use-after-free condition in Thunderbird's IMAP handling code.prefs.js file on disk.prefs.js file (e.g., via a subsequent file-access vector, social engineering, or if the server interaction itself allows data to be sent back) to extract the disclosed heap contents (Mozilla Advisory MFSA2026-86, Red Hat Bugzilla).ID command/response traffic captured in network logs.prefs.js file (e.g., binary-looking or garbled strings in preference values); recent modification timestamps on prefs.js coinciding with IMAP session activity.prefs.js at unusual times.Mozilla has released patched versions that address CVE-2026-84641: Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2. Users should update to one of these versions immediately. No configuration-based workaround has been published; the recommended action is to upgrade. As an additional precaution, users should avoid connecting Thunderbird to untrusted or unknown IMAP servers and ensure IMAP connections use TLS to reduce man-in-the-middle risk (Mozilla Advisory MFSA2026-86, Mozilla Advisory MFSA2026-87, Mozilla Advisory MFSA2026-88).
Mozilla rated this vulnerability as low impact in all three security advisories published on September 1, 2026, noting that scripting-based flaws generally cannot be exploited through email in Thunderbird. Red Hat opened a high-priority security tracking bug (Bug 2527115) for downstream package maintainers. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Mozilla Advisory MFSA2026-86, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."