Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-84637: Thunderbird calendar invites can run hidden programs

CVE-2026-84637 · published 1 day ago
Summary

A crafted calendar invitation can cause Thunderbird on Windows to start a program from the user's computer or network, even though the attachment looks harmless. This lets an attacker run malicious code without the usual warnings. Update Thunderbird to the latest version to eliminate the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mozilla thunderbird All versions
Original advisory text
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the ne...
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-84637 · MITRE
Monitor software like this
Free during beta