The current version of Thunderbird is 157.0.1 (as of 02/10/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2019-11708Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
10.0 critical · over the network, without login · CISA deadline was 13 Jun 22
- CVE-2019-17026Mozilla Firefox And Thunderbird Type Confusion Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 3 May 22
- CVE-2013-1690Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 18 Apr 22
- CVE-2019-11707Mozilla Firefox and Thunderbird Type Confusion Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 13 Jun 22
- CVE-2020-6820Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
8.1 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2020-6819Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
8.1 high · over the network, without login · CISA deadline was 3 May 22
- CVE-2016-9079Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
7.5 high · over the network, without login · CISA deadline was 13 Jul 23
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Thunderbird at a glance
Mozilla Thunderbird is a widely used open-source email client, also common in organizations. Mozilla ships a major release yearly (ESR-style) plus regular security fixes; as a client that renders messages and handles attachments, timely updates matter.
For admins Thunderbird can be centrally managed through policies, covering updates, accounts and features. Security updates should be applied promptly — email is a primary attack vector, and the client parses untrusted content. The built-in updater keeps standalone installs current; managed fleets use the enterprise installer plus policy. Major-version jumps warrant a check of add-ons and account/config compatibility. Manage add-ons and the message-display settings deliberately in sensitive environments. Track the version and its support window.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 157.0.1 | STABLE | 02/10/2026 | – |
| 157.0 | STABLE | 01/10/2026 | – |
| 156.0.1 | STABLE | 23/09/2026 | – |
| 156.0 | STABLE | 16/09/2026 | – |
| 155.0.1 | STABLE | 10/09/2026 | – |
| 155.0 | STABLE | 02/09/2026 | – |
| 154.0 | STABLE | 19/08/2026 | – |
| 153.0.3 | STABLE | 12/08/2026 | – |
| 153.0.2 | STABLE | 05/08/2026 | – |
| 153.0.1 | STABLE | 29/07/2026 | – |
| 153.0 | STABLE | 22/07/2026 | – |
| 152.0.1 | STABLE | 08/07/2026 | – |
Frequently asked questions
- What is the latest version of Thunderbird?
- Thunderbird 157.0.1, released 02/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Thunderbird release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Thunderbird updates?
- Tick Thunderbird off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Thunderbird version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Thunderbird version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/thunderbird)https://patchletter.com/badge/thunderbird.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).