Tech News

Thunderbird 153 Brings a New ESR Base, Native Exchange Support, and 61 Fixes

Mozilla released Thunderbird 153 Meadow on July 21, 2026. On the menu: a fresh start for the ESR branch, a redesigned account manager, support for Microsoft Exchange, and 61 fixed CVEs. Here’s what to remember.

A new ESR release that rolls up a year of monthly builds

Thunderbird 153 arrives at the same time as Firefox 153, with which it shares the Gecko engine, and it is notable because it will become the future base version for the ESR channel (Extended Support Release, designed for businesses). In the announcement published on the official blog, Brian Offredi explains that this new release builds on Thunderbird 140 and on all the features delivered over the past year in the monthly channel. In other words, for organizations staying on the ESR track, this release matters.

Thunderbird ESR 140 will remain supported until mid-September 2026, at which point version 153 will become the only active ESR. That gives you time to test it before rolling it out.

Accounts, Exchange, DoH: what Thunderbird 153 actually changes

Here are the main new features introduced in Thunderbird 153:

  • Account Hub becomes the required starting point

The new setup wizard now opens on Thunderbird’s first launch and covers mail, calendar, and address book. Mozilla highlights improved autodiscover, automatic protocol detection, and automatic configuration of calendars and address books linked to the account.

That does not prevent you, still through this wizard, from manually configuring EWS, IMAP, and POP3 accounts. A Connect with Thundermail button, Mozilla’s in-house mail service, is also built in.

  • Microsoft Exchange is no longer experimental.

Native support via Exchange Web Services, introduced in the monthly channel with Thunderbird 145, has now made its way into Thunderbird 153 (and therefore into ESR). The good news is that Mozilla now claims full support for Exchange servers via EWS: native account creation, reading, managing, and composing messages, with no add-on required.

One caveat, though: this is currently limited to email. Mozilla’s announcement adds two details:

- Microsoft Graph support is already present in the product core, but it is disabled behind a preference while development is being finalized.

- Full Graph support, along with calendar and address book integration, is planned for later this year.

In other words, organizations hoping to fully replace Outlook will still need to wait for calendar and contacts.

  • More security

Version 153 adds support for DNS over HTTPS, opens OAuth connections in the default browser instead of an embedded window, verifies the issuer field in OAuth responses and rejects incomplete responses, and switches Yahoo, AT&T, AOL, and Gmail accounts to PKCE.

  • The interface now matches the system

On the visual side, Thunderbird inherits the operating system’s accent color, with the option to choose a custom shade in the appearance settings. Native notifications gain an Archive action, alongside the existing actions (mark as read, delete, report as spam).

As a reminder, Thunderbird 151 had already laid some of this groundwork on the Thundermail side, a service whose outline Mozilla revealed in 2025 and which becomes usable without installing any add-on in version 153.

61 CVEs fixed, including one reported with help from AI

The release of Thunderbird 153 comes with a fairly large security advisory. Indeed, this bulletin published on July 21, 2026 lists 61 security flaws, including around twenty rated high severity. It includes sandbox escapes, privilege escalations, integer overflows in WebAssembly and graphical components.

"In general, these vulnerabilities cannot be exploited by email in Thunderbird because script execution is disabled when reading emails; however, they still represent potential risks in a browser or browser-like environments.", Mozilla notes.

Security issue CVE-2026-14899 was reported by Kai Engert and... Claude. Artificial intelligence therefore helped uncover this vulnerability in the MIME header parser used when transferring a message. This off-by-one error could read one byte beyond the header buffer, with a risk of application crash.

Source

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.