DSA-6461-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure https://security-tracker.debian.org/tracker/DSA-6461-1
CSIRTS triage
- What
- Multiple security issues in Thunderbird could allow execution of arbitrary code or information disclosure.
- Who is affected
- All Thunderbird users on affected versions.
- Urgency
- Patch should be applied as soon as possible due to remote code execution risk.
- Action
- Update Thunderbird to the patched version released in DSA-6461-1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Thunderbird
Get an email when a new Thunderbird advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00372.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-749340.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749350.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749360.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749390.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749400.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749410.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749420.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749430.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749440.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-749450.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Mozilla Firefox, Firefox ESR and Thunderbird: Multiple Vulnerabilitiescert-bund
- unknownMozilla Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Mozilla products (August 19, 2026)cert-fr-avis
- unknownDSA-6451-1 firefox-esr - security updatedebian
- criticalCVE-2026-74990: Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and…nvd
- criticalCVE-2026-74987: Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some o…nvd
- highCVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firef…nvd
- mediumCVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Fi…nvd
- mediumCVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in…nvd
- mediumCVE-2026-74973: Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Fire…nvd
- mediumCVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed …nvd
- mediumCVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability wa…nvd
More from Debian Security Advisories
- unknownDSA-6464-1 erlang - security update2026-08-25
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6462-1 zfs-linux - security update2026-08-24
- unknownDSA-6463-1 webkit2gtk - security update2026-08-24