An email client displayed on a desktop, surrounded by download, security, Windows compatibility, and performance icons.
Mozilla's Thunderbird 157.0 doesn't add much you can see. It's mostly a list of fixes, and several of them matter to Windows users: an intermittent Gmail sign-in failure, IMAP sent mail that sometimes didn't save, and a status bar that could keep one CPU core pegged after it had nothing left to do. Mozilla also shipped two ESR updates on the same day, 153.4.0 and 140.17.0, and the three releases don't contain the same fixes. If you run Thunderbird across a fleet, check which branch you're on before you assume anything.

What shipped, and when​

Mozilla's release notes date Thunderbird Desktop 157.0 to September 30, 2026, with Thunderbird 153.4.0 ESR released the same day. German site Deskmodder said Mozilla pushed the update out in three versions: 157.0, 153.4.0 ESR and 140.17.0 ESR. The release was also a day late. According to Deskmodder, it was planned for Tuesday, but a second release candidate was uploaded and tested first, so it arrived on Wednesday and is being delivered through the client's built-in updater.

The features went through beta first. Mozilla's beta notes say version 157.0beta was released September 14, 2026, and the final beta, beta 4, followed on September 23.

Summary: One rapid-release update and two ESR updates, all released September 30. Each has its own release notes and its own security advisory.

New for administrators: DisableChat and DisableFileLink​

The two additions for IT departments are narrow but useful. Mozilla's notes list Enterprise policy DisableChat disables Thunderbird Chat functionality and Enterprise policy DisableFileLink disables Thunderbird FileLink functionality.

What they do in practice:

  • DisableChat turns off Thunderbird's built-in chat client. That's useful where chat has to go through approved, logged platforms.
  • DisableFileLink turns off FileLink, Thunderbird's feature for sending large attachments through an online storage service. That matters to organizations with data-loss-prevention rules about where files are allowed to go.

Neither policy is a general switch for every kind of chat or every attachment. Each one targets a single feature. Mozilla's release notes also don't include deployment steps, so get the exact policy syntax from Mozilla's enterprise policy documentation rather than guessing.

There's a related fix for anyone who controls update versions. Mozilla says the AppUpdatePin policy did not prevent Thunderbird from updating beyond pinned version, and that's now corrected. If you pin versions and saw machines move past the pin anyway, this is probably why. The fix appears in both 157.0 and 153.4.0 ESR.

Other changes in 157.0​

  • The port field is optional for manual IMAP/POP setup. Mozilla's beta notes say the IMAP/POP manual config port field is now optional. The official notes don't say how Thunderbird picks a port when you leave it blank, so if your provider uses non-standard ports, keep entering them yourself.
  • OpenPGP remote content. Thunderbird now allows viewing remote content in OpenPGP messages encrypted with integrity protection. That's a specific, limited case. Don't read it as Thunderbird loosening encryption security across the board.
  • RNP tools removed. RNP command-line utilities are no longer included with Thunderbird. Most people won't notice. Mozilla doesn't describe any downstream impact, though, so anyone whose scripts called those bundled tools should check before upgrading.
  • A preference is gone. The preference mailnews.headers.minNumHeaders has been removed. Power users who set it in the Config Editor will lose that tweak.
  • Thundermail add-on. The built-in Thundermail add-on is now version 2.0.16. Deskmodder reports the same version bump in 153.4.0 ESR.

Summary: Mostly housekeeping, but the RNP and preference removals could break scripted or heavily customized setups.

The fixes Windows users should care about most​

Mozilla's 157.0 notes list more than 20 fixes. Grouped by area:

Sign-in and authentication​

  • The headline fix for Windows: Gmail OAuth2 authentication could intermittently fail on Windows. Intermittent sign-in failures are notoriously hard to troubleshoot, so this one is welcome.
  • SMTP OAuth2 failed when large access token exceeded command line length limit
  • Exchange NTLM authentication failed when updated passwords were not saved
  • SMTP AUTH LOGIN could fail after username challenges and close the connection
  • Mozilla's notes add that a custom OAuth endpoint host wrongly required a full URL when it should have accepted just a domain.

IMAP and sending​

  • Sent messages could silently fail to save to the IMAP Sent folder. The silent part is what makes it bad: you'd only find out when you went looking for a message you knew you'd sent.
  • Thunderbird could hang while waiting for the IMAP server's greeting during account setup.
  • Sending didn't fail gracefully when a message had a malformed References header.
  • Pending moves within the same IMAP account could make messages disappear

Interface and performance​

  • The status bar could stay active after activity ended and drive CPU usage to 100%. On a laptop, that means a hot machine and a drained battery.
  • The message list could show the wrong sender.
  • The Ctrl+Shift+K shortcut could fail to open the Quick Filter.

OpenPGP, address books and content​

  • OpenPGP discovery failed to find replacement keys after a key had been revoked, and valid RSA keys could be rejected, which blocked encryption.
  • CardDAV address books could fail to sync when no password prompt was needed.
  • Yahoo emails appeared blank with MIME handlers disabled via mailnews.display.disallow_mime_handlers
  • Inline images could disappear after editing and resaving drafts
  • Message filters could falsely match when a search term failed to evaluate, and account creation in Account Hub could fail with a malformed URI.

Calendar​

  • Recurring events could appear after their configured end date
  • CalDAV task body could remain outdated after syncing changes from another client
  • CalDAV invitations could fail when accepted before the calendar synced

Basic Tutorials also says there have been isolated user reports of trouble with the "Google Calendar Provider" add-on and suggests checking that calendar sync still works after updating. Mozilla's notes don't mention this, so treat it as a quick thing to check, not a confirmed bug.

Summary: If you've been fighting Gmail sign-in failures, missing sent mail or unexplained CPU load, update to 157.0 first and troubleshoot only if the problem continues.

The ESR branches don't get the same fixes​

Mozilla's notes for 153.4.0 ESR are much shorter. Deskmodder's breakdown confirms that 153.4.0 ESR removes the RNP command-line programs and updates the built-in Thundermail add-on to version 2.0.16, plus fixes for the Quick Filter shortcut and the AppUpdatePin policy. Mozilla's notes for that release also list:

  • Nested S/MIME signed parts that could fail to render (this one is in the ESR notes only)
  • The IMAP greeting hang during account setup
  • The intermittent Gmail OAuth2 failure on Windows
  • A "What's New?" link that pointed to the Release channel notes instead of the ESR release notes

ESR users are not getting the full 157.0 list. The CPU-hungry status bar, the IMAP Sent folder fix, the CardDAV and CalDAV repairs, the OpenPGP key fixes and both new enterprise policies don't appear in the 153.4.0 notes. If any of those fixes matter to you, moving to the rapid-release channel may be worth weighing against the stability ESR offers.

Basic Tutorials also describes 140.17.0 as the last release in the 140 ESR series. Mozilla's documentation confirms that 140.17 got a security update, but we couldn't confirm the end-of-life claim from an official lifecycle source. If you're still on 140.x, plan a move to 153.x either way. Sitting on an old ESR branch only gets riskier over time.

The security side​

Basic Tutorials said specific CVEs hadn't been documented yet. In fact, Mozilla's advisories were already public: MFSA 2026-101 covers Thunderbird 157, MFSA 2026-102 covers 140.17 and MFSA 2026-103 covers 153.4. Deskmodder likewise notes security fixes in all three versions.

Advisory 2026-101 rates the 157 update's overall impact as high and lists dozens of individual CVEs. Many are use-after-free bugs, sandbox escapes and memory-boundary errors in parts of the Gecko engine Thunderbird shares with Firefox. Mozilla adds an important caveat: in general, these flaws can't be exploited through email in Thunderbird, because scripting is disabled when reading mail. They're potential risks in browser or browser-like contexts. Individual ratings vary too. One of the bugs Thunderbird itself is exposed to, CVE-2026-103500, is a heap buffer overflow triggered by opening an email of 2 GB or more, and Mozilla rates it low.

The overall "high" label doesn't mean every entry is critical, and the 157 list isn't necessarily the same as the ESR lists. Security teams should read the advisory that matches each deployed branch.

How to update​

  1. Open Thunderbird and, per Basic Tutorials, go to Help → About Thunderbird to check for updates manually.
  2. Let the update download, then restart Thunderbird when prompted.
  3. Open the About window again to confirm you're on 157.0, or 153.4.0 ESR if you're on the extended branch.
  4. Check the things this release touched: send a test message and make sure it shows up in your IMAP Sent folder, confirm that Gmail accounts sign in cleanly, and sync your calendars.

Wikipedia's Thunderbird entry lists supported platforms as Windows 10 or later; macOS 10.15 or later, along with Linux and others. Windows 7 and 8.1 holdouts are out of luck.

The verdict​

Thunderbird 157.0 is a maintenance release, and for an email client that's a good thing. Most people want their mail client to stay out of the way, and these fixes deal with exactly the problems that get in the way: sign-ins that randomly fail, sent mail that disappears and a status bar quietly eating CPU. Admins get two more policy controls and a fixed AppUpdatePin. If you're on ESR, compare the release notes for your branch before telling users their problem has been fixed.

 

References

  1. Thunderbird 157.0: Here Are the Bug Fixes Included in the New Update - Basic Tutorials Basic Tutorials 2026-10-01T03:08:59+00:00
  2. Security Vulnerabilities fixed in Thunderbird 157 — Mozilla mozilla.org
  3. Thunderbird 157.0, 153.4.0 ESR und 140.17.0 ESR mit Sicherheitskorrekturen und mehr - Deskmodder.de deskmodder.de