CVE-2026-84637: Calendar invitation attachments could launch local executables
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 154
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84639
- CVE-2026-84640
- CVE-2026-84641
- CVE-2026-84637
- CVE-2026-84642
- CVE-2026-75874
- CVE-2026-84118
- CVE-2026-84119
- CVE-2026-84120
- CVE-2026-84121
- CVE-2026-84122
- CVE-2026-84123
- CVE-2026-84124
- CVE-2026-84125
- CVE-2026-74952
- CVE-2026-84129
- CVE-2026-84130
- CVE-2026-84131
- CVE-2026-84132
- CVE-2026-84133
- CVE-2026-84134
- CVE-2026-84136
- CVE-2026-84137
- CVE-2026-84139
- CVE-2026-84140
- CVE-2026-84141
- CVE-2026-84143
- CVE-2026-84144
- CVE-2026-84145
Frequently Asked Questions
Which Thunderbird installations are affected?
Thunderbird versions before 154 are affected. The issue was fixed in Thunderbird 154.
What must an attacker do to exploit this issue?
An attacker would need to send a malicious calendar invitation containing a file URI attachment that points to a local or network-hosted executable. Opening the attachment could launch the executable on Windows while bypassing Thunderbird's normal executable-attachment protections.
Does the invitation display setting change the risk?
When the new invitation display is enabled, the malicious attachment may be shown under a misleading filename. This can make the attachment appear less suspicious to the recipient.