Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY304 SECURITY RECORDS

Mozilla

Thunderbird

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-103500 30 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100820 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100818 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100817 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100813 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100811 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100810 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100807 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100805 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100804 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100802 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100801 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100799 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100796 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100795 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-96869 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100794 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100793 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100792 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100788 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100776 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100772 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100769 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ *; Firefox: 140.17 ≤ 140.*, 153.4 ≤ 153.*, 157 ≤ * Update reference ↗
CVE-2026-100768 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100764 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100763 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-100761 29 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 157 ≤ *; Firefox: 157 ≤ * Update reference ↗
CVE-2026-92240 15 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.16 ≤ 140.*, 153.3 ≤ 153.*, 156 ≤ * Update reference ↗
CVE-2026-92239 15 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.16 ≤ 140.*, 153.3 ≤ 153.*, 156 ≤ * Update reference ↗
CVE-2026-92238 15 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.16 ≤ 140.*, 153.3 ≤ 153.*, 156 ≤ * Update reference ↗
CVE-2026-84642 1 Sep 2026 See the vendor and CVE records for the affected range. 153.2 ≤ 153.*; 155 ≤ * Update reference ↗
CVE-2026-84641 1 Sep 2026 See the vendor and CVE records for the affected range. 140.15 ≤ 140.*; 153.2 ≤ 153.*; 155 ≤ * Update reference ↗
CVE-2026-84640 1 Sep 2026 See the vendor and CVE records for the affected range. 140.15 ≤ 140.*; 153.2 ≤ 153.*; 155 ≤ * Update reference ↗
CVE-2026-84639 1 Sep 2026 See the vendor and CVE records for the affected range. Thunderbird: 140.15 ≤ 140.*, 153.2 ≤ 153.*, 155 ≤ * Update reference ↗
CVE-2026-84637 1 Sep 2026 See the vendor and CVE records for the affected range. 153.2 ≤ 153.*; 154 ≤ * Update reference ↗
CVE-2026-14899 22 Jul 2026 See the vendor and CVE records for the affected range. 140.13 ≤ 140.*; 153 ≤ * Update reference ↗
CVE-2026-57963 1 Jul 2026 See the vendor and CVE records for the affected range. 140.12.1 ≤ 140.*; 152.0.1 ≤ * Update reference ↗
CVE-2026-57962 1 Jul 2026 See the vendor and CVE records for the affected range. 140.12.1 ≤ 140.*; 152.0.1 ≤ * Update reference ↗
CVE-2026-4371 24 Mar 2026 See the vendor and CVE records for the affected range. 140.9 ≤ 140.*; 149 ≤ * Update reference ↗
CVE-2026-3889 24 Mar 2026 See the vendor and CVE records for the affected range. 140.9 ≤ 140.*; 149 ≤ * Update reference ↗
CVE-2026-0818 28 Jan 2026 See the vendor and CVE records for the affected range. 140.7.1 ≤ 140.*; 147.0.1 ≤ * Update reference ↗
CVE-2025-5986 11 Jun 2025 See the vendor and CVE records for the affected range. 128.11.1 ≤ 128.*; 139.0.2 ≤ * Update reference ↗
CVE-2025-5262 27 May 2025 unspecified < 139; unspecified < 128.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-3932 14 May 2025 See the vendor and CVE records for the affected range. 128.10.1 ≤ 128.*; 138.0.1 ≤ * Update reference ↗
CVE-2025-3909 14 May 2025 See the vendor and CVE records for the affected range. 128.10.1 ≤ 128.*; 138.0.1 ≤ * Update reference ↗
CVE-2025-3875 14 May 2025 See the vendor and CVE records for the affected range. 128.10.1 ≤ 128.*; 138.0.1 ≤ * Update reference ↗
CVE-2025-3523 15 Apr 2025 See the vendor and CVE records for the affected range. 128.9.2 ≤ 128.*; 137.0.2 ≤ * Update reference ↗
CVE-2025-2830 15 Apr 2025 See the vendor and CVE records for the affected range. 128.9.2 ≤ 128.*; 137.0.2 ≤ * Update reference ↗
CVE-2025-3522 15 Apr 2025 See the vendor and CVE records for the affected range. 128.9.2 ≤ 128.*; 137.0.2 ≤ * Update reference ↗
CVE-2025-26695 10 Mar 2025 See the vendor and CVE records for the affected range. 128.8 ≤ 128.*; 136 ≤ * Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.