Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Debian Security

DSA-6267-1 thunderbird - security update

Multiple critical vulnerabilities in Thunderbird (CVE-2026-8090, CVE-2026-8092, CVE-2026-8094) could lead to arbitrary code execution, with CVSS scores ranging from High (7.3) to Critical (9.8). Affected versions include Thunderbird versions prior to 140.10.2 and versions 150.0 through 150.0.1. The Debian project has addressed these issues in Thunderbird version 1:140.10.2esr-1~deb12u1 for Bookworm and version 1:140.10.2esr-1~deb13u1 for Trixie.
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6267-1] thunderbird security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6267-1] thunderbird security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Thu, 14 May 2026 12:05:49 +0000 Message-id: <[🔎] agW6nbx_cL8k3m7l@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6267-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 14, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2026-8090 CVE-2026-8092 CVE-2026-8094 Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.10.2esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 1:140.10.2esr-1~deb13u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoFujoACgkQEMKTtsN8 TjYRXg//cWyDwxx//oJ6FEYVdYlsvXd/Z7qLWCpHjA64PRMAkKGpYZI+JTagFvDP goyra7AqfOF09z1wBpmGZDF7QLS4oTxHlVPLzoBm3hG911Cq/7HnzeqNb1pDlUAY mFV3yvx76yZ5ZHPBVTN4AYKHlXlnQ8BpiDEzQblme4pk/xnuAH3jtKFIkPTKfnZ4 DRb9YzhZb7E7LywMwk3sA6OBUUG/mf8BcPgUPN8kZai6+YaGmsukYqfMIcjkf67c S56LZwy5AqHhm7N5EH/5KXITzTBjtqnWPUCOj83Szzy5cHgJN0TzB8wvuteenzEk ryj/rm+pVA/CV+flKsugLF1YkjztbyLHybCkEY5uH3zSNoB6QT7hOqIplaGNIISQ LFVh+jsOYFtd1dXoGIAxmi5pHnAvNIcEVIu9UX5Sm1XvF/AoOcmr3ASY2/aLHVGh 0l2ZzKE2hSsO/21Mrr+q2dA+/JZphblwpaXWaJjxNXkynXwMZnThE5Z5ec7laxwq e1xMhXZTYzPWx9a5jj/2vuBdciZWHI56FoaOpVPaf6LiI5+bi3tc2b5uSi+H3Kc+ hv57y4OaIzCFyLVT9dcug5clCDSY1dxwo70jH8A3ojRkk9KalgevWgnH+/NMz7ms E8duqT+h6i0oVxQ/2wiQd6ik6pMMKXLOFIjjk8sAzCcfeW+P7jY= =XiKo -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6266-1] nghttp2 security update Next by Date: [SECURITY] [DSA 6268-1] ffmpeg security update Previous by thread: [SECURITY] [DSA 6266-1] nghttp2 security update Next by thread: [SECURITY] [DSA 6268-1] ffmpeg security update Index(es): Date Thread

Share this article