Thunderbird 157 Fixes 100% CPU Bug and 76 Security Flaws
If you use Mozilla Thunderbird as your email client, I strongly encourage you to install Thunderbird 157. This release fixes several bugs, including the one that causes the processor to spike to 100% even when there is nothing left to process, as well as the bug where sent emails are not saved in the Sent folder.
Mozilla released Thunderbird 157 on September 29, 2026, and this version does not bring any major new user-facing features. However, it improves the stability of the open source email client thanks to several fixes.
The most visible bug for users affects the status bar at the bottom of the window, which displays the progress of ongoing operations (checking mail, sending a message, etc.). Once the operation was complete, it could remain active as if a task were still running. As a result, the CPU could stay locked at 100%, even though Thunderbird had nothing left to do. This has been fixed in version 157.
Another disruptive bug has also been fixed: the message list could display the wrong sender. In addition, sent messages might not be saved in the Sent folder of an IMAP account, with no visible error. The kind of problem you only discover the day you need proof that an email was sent...
OpenPGP, authentication, and IMAP: the main fixes
OpenPGP users are affected by this update. Here are the key points from the release notes published by Mozilla:
- RSA keys rejected: valid OpenPGP RSA keys could be refused, which simply prevented a message from being encrypted.
- Revoked keys: OpenPGP key discovery can now find the replacement key when a key has been revoked.
- Remote content: Thunderbird can now display remote content in OpenPGP messages encrypted with integrity protection.
- OAuth2: intermittent OAuth2 authentication failures with Gmail on Windows have been fixed. The same applies to sending via SMTP with OAuth2, which failed when the access token was too large and exceeded the maximum length allowed for a command.
- Exchange and NTLM: NTLM authentication on Exchange failed when the updated password had not been saved.
- IMAP: Thunderbird could freeze while waiting for the IMAP server greeting during account setup. In addition, pending moves within the same IMAP account could cause messages to disappear.
On the calendar and contacts side, recurring events no longer appear after their end date, CalDAV invitations accepted before calendar synchronization work again, and some CardDAV address books sync correctly again. On the practical side, there is a small improvement: when manually configuring an IMAP or POP account, the port field is now optional.
For admins, 2 new settings
If you use Thunderbird in the enterprise and configure it through policy (ADMX templates), note that Thunderbird 157 introduces two new options:
- DisableChat: disables the built-in instant messaging feature in Thunderbird.
- DisableFileLink: disables FileLink, the feature that lets you send a large attachment through an online storage service by sharing a link instead of the file itself.
There is also a fix directly related to these policies: the AppUpdatePin setting, which is used to lock Thunderbird to a specific version, did not prevent the client from updating beyond the version pinned in the policy. Quite ironic... The setting will now work as it should have from the start.
Mozilla also fixed security vulnerabilities in Thunderbird 157. The official security advisory lists 76 fixed flaws: 38 important, 29 moderate, and 9 low severity. No vulnerability is critical. Almost all of these flaws affect the engine shared with Firefox. "As a rule, these flaws cannot be exploited by email in Thunderbird because script execution is disabled when reading emails," Mozilla notes. Only one issue is specific to the mail client: CVE-2026-103500, a buffer overflow triggered when opening an email that is 2 GB or larger.


