Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-84637

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-84637


Contact Us

Shodan ® - All rights reserved