Thunderbird ESR
MZLA Technologies / Mozilla · current 153.4.0
The current version of Thunderbird ESR is 153.4.0 (as of 30/09/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists this vulnerability in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2016-9079Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
7.5 high · over the network, without login · CISA deadline was 13 Jul 23
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
WID-SEC-W-2026-3375 · 9 Oct
- Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen
WID-SEC-W-2026-3654 · 9 Oct
- Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
WID-SEC-W-2026-3132 · 8 Oct
- Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
WID-SEC-W-2026-2458 · 8 Oct
- Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen
WID-SEC-W-2026-2911 · 8 Oct
- Mozilla Thunderbird, Firefox ESR und Firefox: Mehrere Schwachstellen
WID-SEC-W-2026-1228 · 22 Sept
- Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen
WID-SEC-W-2026-1296 · 22 Sept
- Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen
WID-SEC-W-2026-1427 · 22 Sept
Thunderbird ESR at a glance
Thunderbird ESR is the extended-support branch of the open-source email client from MZLA and Mozilla. While the regular branch adds features monthly, an ESR line keeps the same feature set for a year and receives only security and bug fixes. On managed desktops this is the usual choice, because policies, add-ons and user training stay stable.
Maintenance releases follow the security-advisory cadence, largely in step with Firefox ESR. Once a year the ESR base moves to a new major version. During the transition two ESR lines are maintained in parallel, so the migration can be planned rather than forced.
When updating, what matters most is that security fixes land promptly: email is a primary attack path and the client parses untrusted content. Managed environments deploy through the enterprise installer and central policies rather than the built-in updater. Before moving to a new ESR major, check add-ons, account and certificate configuration, and back up the profile directory.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 153.4.0 | LTS | 30/09/2026 | Release notes → |
| 153.3.1 | LTS | 18/09/2026 | Release notes → |
| 153.3.0 | LTS | 16/09/2026 | Release notes → |
| 153.2.0 | LTS | 02/09/2026 | Release notes → |
| 153.1.1 | LTS | 27/08/2026 | Release notes → |
| 153.1.0 | LTS | 19/08/2026 | Release notes → |
| 153.0.3 | LTS | 18/08/2026 | Release notes → |
| 153.0.2 | LTS | 18/08/2026 | Release notes → |
| 153.0.1 | LTS | 18/08/2026 | Release notes → |
| 153.0 | LTS | 18/08/2026 | Release notes → |
| 140.17.0 | LTS | 30/09/2026 | Release notes → |
| 140.16.0 | LTS | 16/09/2026 | Release notes → |
| 140.15.0 | LTS | 02/09/2026 | Release notes → |
| 140.14.1 | LTS | 26/08/2026 | Release notes → |
| 140.14.0 | LTS | 19/08/2026 | Release notes → |
| 140.13.0 | LTS | 18/08/2026 | Release notes → |
| 140.12.1 | LTS | 18/08/2026 | Release notes → |
| 140.12.0 | LTS | 18/08/2026 | Release notes → |
| 140.11.1 | LTS | 18/08/2026 | Release notes → |
| 140.11.0 | LTS | 18/08/2026 | Release notes → |
| 140.10.2 | LTS | 18/08/2026 | Release notes → |
| 140.10.1 | LTS | 18/08/2026 | Release notes → |
| 140.10.0 | LTS | 18/08/2026 | Release notes → |
| 140.9.1 | LTS | 18/08/2026 | Release notes → |
| 140.9.0 | LTS | 18/08/2026 | Release notes → |
| 140.8.1 | LTS | 18/08/2026 | Release notes → |
| 140.8.0 | LTS | 18/08/2026 | Release notes → |
| 140.7.2 | LTS | 18/08/2026 | Release notes → |
| 140.7.1 | LTS | 18/08/2026 | Release notes → |
| 140.7.0 | LTS | 18/08/2026 | Release notes → |
| 140.6.0 | LTS | 18/08/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Thunderbird ESR?
- Thunderbird ESR 153.4.0, released 30/09/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Thunderbird ESR release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Thunderbird ESR updates?
- Tick Thunderbird ESR off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Thunderbird ESR version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Thunderbird ESR version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/mozilla-thunderbird-esr)https://patchletter.com/badge/mozilla-thunderbird-esr.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).