CVE-2026-84145
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of me
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 1, 2026 · Last modified: Sep 1, 2026 · CWE-119
Not enough EPSS history yet.
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2054640%2C2054650%2C2054652%2C2055693%2C2055705%2C2058051%2C2058652%2C2058660%2C2059027%2C2061220%2C2061242%2C2061285%2C2061300%2C2061316%2C2061397
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/buglist.cgi?bug_id=2058001%2C2059139%2C2062400%2C2062419
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2055678
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-82/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-83/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-84/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-85/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-86/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-87/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-88/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-9637——
———A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover6hCVE-2026-828204.3 MED—
———A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be applied to remediate this issue. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."7hCVE-2026-826808.8 HIG—
——0A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.1dCVE-2026-826772.4 LOW—
——0A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.1dCVE-2026-826312.2 LOW28.8%
——9A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue.2dCVE-2026-826235.3 MED33.6%
——10A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.1d