CVE-2025-26696
CVSS 3.1 Score 7 of 10 (high)
Details
Published Mar 10, 2025
Updated: Apr 3, 2025
CWE ID 290
Summary
CVE-2025-26696 is a vulnerability that affects Thunderbird versions 128.x and 135.x. Maliciously crafted MIME email messages, which appear to contain encrypted OpenPGP messages, are wrongly displayed as encrypted by Thunderbird. In reality, these messages contain OpenPGP signed messages, which can potentially expose users to security risks. It is crucial that users update their Thunderbird software to the latest version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.