RHSA-2026:2286HighCVSS 7.5

Red Hat Security Advisory: thunderbird security update

Published
February 9, 2026
Last Modified
June 30, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-14327 — firefox: Spoofing issue in the Downloads Panel component CVE-2026-0877 — firefox: thunderbird: Mitigation bypass in the DOM: Security component CVE-2026-0878 — firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-0879 — firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component CVE-2026-0880 — firefox: thunderbird: Sandbox escape due to integer overflow in the Graphics component CVE-2026-0882 — firefox: thunderbird: Use-after-free in the IPC component CVE-2026-0883 — firefox: thunderbird: Information disclosure in the Networking component CVE-2026-0884 — firefox: thunderbird: Use-after-free in the JavaScript Engine component CVE-2026-0885 — firefox: thunderbird: Use-after-free in the JavaScript: GC component CVE-2026-0886 — firefox: thunderbird: Incorrect boundary conditions in the Graphics component CVE-2026-0887 — firefox: thunderbird: Clickjacking issue, information disclosure in the PDF Viewer component CVE-2026-0890 — firefox: thunderbird: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component CVE-2026-0891 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147

🔗 References (16)