RHSA-2026:26270HighCVSS 7.5

Red Hat Security Advisory: thunderbird security update

Published
June 16, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2026-8090 — firefox: thunderbird: Use-after-free in the DOM: Networking component CVE-2026-8092 — firefox: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 CVE-2026-8094 — firefox: thunderbird: Other issue in the WebRTC component CVE-2026-8388 — firefox: thunderbird: Incorrect boundary conditions in the JavaScript Engine: JIT component CVE-2026-8391 — firefox: thunderbird: Other issue in the JavaScript Engine component CVE-2026-8401 — firefox: thunderbird: Sandbox escape in the Profile Backup component CVE-2026-8946 — firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: Web Codecs component CVE-2026-8947 — firefox: thunderbird: Use-after-free in the DOM: Bindings (WebIDL) component CVE-2026-8950 — firefox: Same-origin policy bypass in the Networking: HTTP component CVE-2026-8953 — firefox: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-8954 — firefox: Incorrect boundary conditions, integer overflow in the Audio/Video component CVE-2026-8955 — firefox: thunderbird: Privilege escalation in the DOM: Workers component CVE-2026-8956 — firefox: Integer overflow in the Networking: JAR component CVE-2026-8957 — firefox: Privilege escalation in the Enterprise Policies component CVE-2026-8958 — firefox: Information disclosure, sandbox escape in the Security: Process Sandboxing component CVE-2026-8959 — firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-8961 — firefox: Spoofing issue in the Form Autofill component CVE-2026-8962 — firefox: Mitigation bypass in the DOM: Security component CVE-2026-8968 — firefox: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component CVE-2026-8970 — firefox: Privilege escalation in the Security component CVE-2026-8974 — firefox: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 CVE-2026-8975 — firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151

🎯 Affected products10

  • Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • thunderbird-0:140.11.0-1.el8_4.src as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • thunderbird-0:140.11.0-1.el8_4.src as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • thunderbird-0:140.11.0-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • thunderbird-0:140.11.0-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • thunderbird-debuginfo-0:140.11.0-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • thunderbird-debuginfo-0:140.11.0-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • thunderbird-debugsource-0:140.11.0-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • thunderbird-debugsource-0:140.11.0-1.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (22)