# Mozilla patches Thunderbird data integrity flaws

Published: 2026-07-02 · Severity: medium
Canonical: https://vorant.io/reports/f60c7293-db5f-566d-84c6-9b2d9fd27c9b/mozilla-patches-thunderbird-data-integrity-flaws

> Mozilla released updates for Thunderbird versions 140.12.1 and 152.0.1 addressing multiple vulnerabilities that could lead to data integrity compromise and denial of service.

The French CERT has issued an advisory regarding multiple security vulnerabilities discovered in Mozilla Thunderbird. The vulnerabilities affect versions prior to 140.12.1 and versions prior to 152.0.1. According to the advisory, these flaws could allow an attacker to compromise the integrity of data and cause denial of service conditions.

Mozilla has released security bulletins MFSA2026-63 and MFSA2026-64 on June 30, 2026, addressing these issues. The vulnerabilities are tracked as CVE-2026-57962 and CVE-2026-57963. Users are advised to consult Mozilla's security advisories and apply the available patches to mitigate these risks.

The advisory emphasizes the importance of updating to the patched versions to protect against potential attacks that could exploit these vulnerabilities to manipulate data or disrupt email service availability.

## Mentioned in this report

- Vulnerabilities: CVE-2026-57962, CVE-2026-57963

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0827

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f60c7293-db5f-566d-84c6-9b2d9fd27c9b/mozilla-patches-thunderbird-data-integrity-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
