
Mozilla Thunderbird fixes CVE-2026-0818, a CSS-based exfiltration bug that could leak content from partially encrypted emails when remote content is allowed. Update to version 140.7.1. https://threatcluster.io/cluster/mozilla-thunderbird-css-exfiltration-vulnerability-patched-c06ec952
Post summary
Mozilla Thunderbird released patch 140.7.1 to address CVE-2026-0818, a CSS-based exfiltration vulnerability that could leak content from partially encrypted emails when remote content is permitted.


