CVE-2026-84637

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE

Description

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references