Mozilla Thunderbird Calendar Invitation File URI Attachment Execution Vulnerability (CVE-2026-84637)

Release Date: 1st September 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to all users of the Mozilla Thunderbird email client, including Organizations, System/Network administrators, and members of the general public. This alert is intended to be understood by both technical and general readers.

What is it?

CVE-2026-84637 affects Mozilla Thunderbird's handling of calendar invitations. A malicious calendar invitation can carry a file URI attachment that, when opened, launches a local or network-hosted executable on Windows, bypassing Thunderbird's normal protections against opening executable attachments directly. With Thunderbird's newer invitation-display feature enabled, the malicious attachment can additionally be shown to the victim under a misleading, disguised filename. This is a separate Mozilla security release (MFSA 2026-87) from the Firefox 155 release already covered by CERTVU Advisory 236 (CVE-2026-84119) – noted here since both concern Mozilla products but address different components and different underlying bugs, so Advisory 236 does not already cover this issue.

Reference

  1. https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/
  2. https://www.cve.org/CVERecord?id=CVE-2026-84637