< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Mozilla and Microsoft patch critical software vulnerabilities

Mozilla has released patches for a critical vulnerability in Thunderbird (CVE-2026-84637) affecting Windows users. The flaw allows attackers to trigger local or network-based programs through specially crafted calendar invitations. By exploiting a file-URI in these invitations, attackers can bypass security mechanisms to execute files, sometimes using misleading filenames to deceive users. Fixes are available in Thunderbird versions 154 and 153.2.

Separately, Microsoft has patched a critical remote code execution (RCE) vulnerability in Entra ID (CVE-2026-69836). The flaw, a server-side deserialization error, carries a CVSS score of 10.0 because it requires low complexity and no user interaction to execute code over a network. While initial reports suggested the flaw was being exploited, Microsoft clarified that it has not been actively used in attacks. Because Entra ID is a managed service, the fix was applied server-side by Microsoft, requiring no action from customers.

Entities

CISA · Entra ID · Microsoft · Mozilla · Thunderbird