Thunderbird

MZLA / Mozilla · current 157.0.1

Are you MZLA / Mozilla? Claim this page

The current version of Thunderbird is 157.0.1 (as of 02/10/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2019-11708Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

    10.0 critical · over the network, without login · CISA deadline was 13 Jun 22

  • CVE-2019-17026Mozilla Firefox And Thunderbird Type Confusion Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 3 May 22

  • CVE-2013-1690Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 18 Apr 22

  • CVE-2019-11707Mozilla Firefox and Thunderbird Type Confusion Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 13 Jun 22

  • CVE-2020-6820Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    8.1 high · over the network, without login · CISA deadline was 3 May 22

  • CVE-2020-6819Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    8.1 high · over the network, without login · CISA deadline was 3 May 22

  • CVE-2016-9079Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

    7.5 high · over the network, without login · CISA deadline was 13 Jul 23

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

Thunderbird at a glance

Mozilla Thunderbird is a widely used open-source email client, also common in organizations. Mozilla ships a major release yearly (ESR-style) plus regular security fixes; as a client that renders messages and handles attachments, timely updates matter.

For admins Thunderbird can be centrally managed through policies, covering updates, accounts and features. Security updates should be applied promptly — email is a primary attack vector, and the client parses untrusted content. The built-in updater keeps standalone installs current; managed fleets use the enterprise installer plus policy. Major-version jumps warrant a check of add-ons and account/config compatibility. Manage add-ons and the message-display settings deliberately in sensitive environments. Track the version and its support window.

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
157.0.1STABLE02/10/2026–
157.0STABLE01/10/2026–
156.0.1STABLE23/09/2026–
156.0STABLE16/09/2026–
155.0.1STABLE10/09/2026–
155.0STABLE02/09/2026–
154.0STABLE19/08/2026–
153.0.3STABLE12/08/2026–
153.0.2STABLE05/08/2026–
153.0.1STABLE29/07/2026–
153.0STABLE22/07/2026–
152.0.1STABLE08/07/2026–

Frequently asked questions

What is the latest version of Thunderbird?
Thunderbird 157.0.1, released 02/10/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Thunderbird release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Thunderbird updates?
Tick Thunderbird off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Thunderbird version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Thunderbird version and keeps it up to date. Anyone may embed it, no account needed.

Thunderbird badge
[![Thunderbird](https://patchletter.com/badge/thunderbird.svg)](https://patchletter.com/en/software/thunderbird)
https://patchletter.com/badge/thunderbird.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Browsers & Clients