Thunderbird
MZLA / Mozilla · current 154.0
The current version of Thunderbird is 154.0 (as of 19/08/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2019-11708Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
10.0 critical · over the network, without login · CISA deadline was 13 Jun 22
- CVE-2019-17026Mozilla Firefox And Thunderbird Type Confusion Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 3 May 22
- CVE-2013-1690Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 18 Apr 22
- CVE-2019-11707Mozilla Firefox and Thunderbird Type Confusion Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 13 Jun 22
- CVE-2020-6820Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
8.1 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2020-6819Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
8.1 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2016-9079Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
7.5 high · over the network, without login · CISA deadline was 13 Jul 23
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Thunderbird at a glance
Mozilla Thunderbird is a widely used open-source email client, also common in organizations. Mozilla ships a major release yearly (ESR-style) plus regular security fixes; as a client that renders messages and handles attachments, timely updates matter.
For admins Thunderbird can be centrally managed through policies, covering updates, accounts and features. Security updates should be applied promptly — email is a primary attack vector, and the client parses untrusted content. The built-in updater keeps standalone installs current; managed fleets use the enterprise installer plus policy. Major-version jumps warrant a check of add-ons and account/config compatibility. Manage add-ons and the message-display settings deliberately in sensitive environments. Track the version and its support window.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 154.0 | STABLE | 19/08/2026 | – |
| 153.0.3 | STABLE | 12/08/2026 | – |
| 153.0.2 | STABLE | 05/08/2026 | – |
| 153.0.1 | STABLE | 29/07/2026 | – |
| 153.0 | STABLE | 22/07/2026 | – |
| 152.0.1 | STABLE | 08/07/2026 | – |
Frequently asked questions
- What is the latest version of Thunderbird?
- Thunderbird 154.0, released 19/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Thunderbird release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Thunderbird updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Thunderbird update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch ThunderbirdEmbed this badge
Shows the current Thunderbird version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/thunderbird)https://patchletter.com/badge/thunderbird.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).