CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.13 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.13 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 153 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.13 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 153
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-16349
- CVE-2026-16350
- CVE-2026-16362
- CVE-2026-16351
- CVE-2026-16352
- CVE-2026-16363
- CVE-2026-16364
- CVE-2026-16365
- CVE-2026-16366
- CVE-2026-16353
- CVE-2026-16354
- CVE-2026-16367
- CVE-2026-16368
- CVE-2026-16369
- CVE-2026-16355
- CVE-2026-16356
- CVE-2026-16357
- CVE-2026-16370
- CVE-2026-16371
- CVE-2026-16372
- CVE-2026-16373
- CVE-2026-16374
- CVE-2026-16375
- CVE-2026-16376
- CVE-2026-16377
- CVE-2026-16378
- CVE-2026-16379
- CVE-2026-16358
- CVE-2026-16380
- CVE-2026-16381
- CVE-2026-16382
- CVE-2026-16383
- CVE-2026-16384
- CVE-2026-16385
- CVE-2026-16386
- CVE-2026-16387
- CVE-2026-16388
- CVE-2026-16389
- CVE-2026-16390
- CVE-2026-16391
- CVE-2026-16392
- CVE-2026-16393
- CVE-2026-16359
- CVE-2026-16394
- CVE-2026-16395
- CVE-2026-16396
- CVE-2026-16397
- CVE-2026-16398
- CVE-2026-16399
- CVE-2026-16400
- CVE-2026-16401
- CVE-2026-16402
- CVE-2026-16403
- CVE-2026-16404
- CVE-2026-16405
- CVE-2026-16406
- CVE-2026-16407
- CVE-2026-16408
- CVE-2026-16409
- CVE-2026-16410
- CVE-2026-16411
- CVE-2026-16412
- CVE-2026-16360
- CVE-2026-15718
- CVE-2026-15719
- CVE-2026-16361
- CVE-2026-14899
Frequently Asked Questions
What is the severity of CVE-2026-16412?
CVE-2026-16412 has a critical severity rating of 9.8 according to the CVSS 3.1 score.
How do I fix CVE-2026-16412?
To fix CVE-2026-16412, users should upgrade to Thunderbird ESR 140.13 or Thunderbird 153.
What type of vulnerability is CVE-2026-16412?
CVE-2026-16412 is classified as a memory safety bug that could potentially lead to memory corruption and arbitrary code execution.
Which software is affected by CVE-2026-16412?
The affected software includes Mozilla Firefox ESR 140.12, Firefox 152, and their respective derivatives.
When was CVE-2026-16412 published?
CVE-2026-16412 was published on July 21, 2026.