Thunderbird 156 Released with OAuth Improvements, OpenPGP Updates, and Major Linux Fixes
The Thunderbird team has officially released Thunderbird 156, bringing another round of new features, security improvements, authentication enhancements, and reliability fixes to the popular open-source email client. Released on September 15, 2026, the update is available for Linux alongside Windows and macOS.
Thunderbird 156 is not a dramatic redesign of the desktop mail client. Instead, it concentrates on improving areas that matter to everyday users and system administrators, including OAuth authentication, OpenPGP, POP3, IMAP, Exchange Web Services, SMTP, attachments, calendars, enterprise policies, and security.
For Linux users in particular, the release delivers several fixes affecting common mail protocols and account configurations while retaining support for Linux environments using GTK+ 3.14 or newer.
Thunderbird 156 Arrives on Linux
Thunderbird 156 follows version 154, which arrived in August with features including optional system tray operation and Microsoft Graph support for Microsoft 365.
Version 156 continues the project's monthly release cycle with a more targeted collection of authentication, security, compatibility, and reliability improvements.
According to Thunderbird's official release notes, version 156 requires:
- Linux: GTK+ 3.14 or newer
- Windows: Windows 10 or newer
- macOS: macOS 10.15 or newer
Thunderbird 156 was officially released on September 15.
Linux distribution availability will vary because distributions can package Thunderbird according to their own schedules. Users receiving Thunderbird through another packaging channel may therefore see version 156 at a different time.
Custom OAuth Support Expands
One of the most significant areas of development in Thunderbird 156 is OAuth authentication.
Thunderbird now supports custom OAuth configurations containing an issuer ID and client secret for IMAP and POP3 accounts. Custom OAuth support has also been extended specifically to POP3.
OAuth has become increasingly important as email providers move away from conventional username-and-password authentication toward token-based authentication.
For Thunderbird, broader custom OAuth support means users and organizations have greater flexibility when connecting the client to mail services that don't fit Thunderbird's predefined provider configurations.
This can be particularly useful in enterprise environments, self-hosted infrastructure, and organizations operating their own identity systems.
Exchange Custom OAuth Setup Fixed
Exchange users receive an important related correction.
Thunderbird 156 fixes an issue that prevented users from properly setting up custom OAuth authentication for Exchange accounts.
Exchange and Microsoft 365 compatibility has become an increasingly important part of Thunderbird development.
Thunderbird 154 enabled Microsoft Graph support for Microsoft 365, and version 156 continues improving the authentication and synchronization infrastructure surrounding Microsoft environments.
For Linux users who need access to workplace Exchange accounts without switching to a proprietary desktop mail application, these incremental improvements are particularly significant.
Yandex Gets External Browser Authentication
Thunderbird 156 also enables an external browser login flow for Yandex accounts.
Rather than performing the entire authentication sequence inside Thunderbird, the login can take place through the user's browser.
External browser authentication is increasingly common with OAuth-based services because the email client doesn't need to directly handle every part of the provider's login interface.
Thunderbird also fixes an issue where external-browser OAuth authentication could fail if a browser preconnection closed before the authentication process completed.
Together, these changes should make browser-based account authentication more dependable.
OpenPGP Gets a New Debugging Capability
Thunderbird's integrated OpenPGP functionality also receives an improvement.
OpenPGP key properties can now output debugging information directly to Thunderbird's Error Console.
Most ordinary users will probably never need this functionality, but it can be valuable when diagnosing problems involving encryption keys or OpenPGP configuration.
Thunderbird has provided integrated OpenPGP support for several years, eliminating the need for many users to install a separate extension simply to encrypt and digitally sign messages.
Improving the diagnostic tools surrounding that implementation should make complicated encryption problems easier to investigate.
External GnuPG Signing Bug Fixed
Another OpenPGP correction affects users who integrate Thunderbird with an external GnuPG installation.
Previously, message signing could fail when the OpenPGP primary key itself wasn't capable of signing, even when an appropriate signing subkey existed.
Thunderbird 156 fixes this behavior.
This is an important distinction in more advanced OpenPGP configurations, where primary keys and subkeys may deliberately have different capabilities.
Users who maintain separate signing subkeys should therefore see more reliable behavior when Thunderbird is configured to use external GnuPG.
Remote Content Security in Encrypted Messages Fixed
Thunderbird 156 includes an important privacy and security-related correction involving encrypted messages.
Remote content could previously load in an encrypted email opened directly from a file. That behavior has now been fixed.
Remote resources in email can potentially reveal information to external servers when loaded, which is why email clients typically provide controls over remote content.
Correctly enforcing those protections becomes particularly important for encrypted correspondence, where users reasonably expect stricter privacy behavior.
Thunderbird 156 Includes Security Fixes
Mozilla has separately published a security advisory covering vulnerabilities corrected in Thunderbird 156.
The advisory assigns the release an overall high impact rating and documents multiple vulnerabilities addressed by the update.
One of those issues, CVE-2026-92238, involves ambiguous parsing of email headers. Mozilla says a maliciously constructed header could cause multiple fields to be interpreted as one and could potentially lead to memory-safety problems.
Another documented vulnerability, CVE-2026-92239, involves a buffer overrun in IMAP.
Mozilla notes that scripting is disabled while reading mail in Thunderbird, which limits the exploitability of several browser-engine vulnerabilities in the normal email-reading context. Nevertheless, keeping Thunderbird updated remains important because the application shares substantial underlying technology with Mozilla's broader platform.
New Enterprise Policies Give Administrators More Control
Organizations deploying Thunderbird across managed computers receive several new enterprise policies.
Thunderbird 156 introduces:
DisableUpdateSettingsDisableDataCollectionSettingsDisableMessageForwardingFilters
The first prevents users from modifying Thunderbird's update settings, while the second prevents changes to data-collection settings.
The third is particularly interesting for security-conscious organizations because it prevents message filters from automatically forwarding email.
Automatic forwarding can create data-governance and security concerns in managed environments, especially when corporate messages are redirected to external accounts.
Giving administrators a policy-level mechanism to disable that functionality makes Thunderbird easier to control in enterprise deployments.
IMAP Folder Discovery Becomes Faster
One potentially noticeable performance fix involves IMAP accounts containing large numbers of folders.
Thunderbird could become slow while loading messages because it was simultaneously discovering a large number of IMAP folders.
Version 156 addresses that performance problem.
Users with relatively simple personal email accounts may never have encountered it, but corporate mailboxes and long-running accounts can contain hundreds or even thousands of folders.
Reducing overhead during folder discovery should make Thunderbird feel more responsive in those environments.
IMAP Subscription Problems Corrected
Another IMAP fix concerns subscribing to folders.
Attempting to subscribe to an IMAP folder and one of its subfolders at the same time could result in the subfolder not being subscribed correctly.
Thunderbird 156 fixes the problem.
The release also addresses situations where renaming a folder could unexpectedly reset that folder's settings.
These aren't headline features, but they improve the predictability of everyday mailbox management.
POP3 Receives Multiple Improvements
Despite IMAP becoming dominant for multi-device email, Thunderbird continues supporting POP3, and version 156 contains several fixes specifically for POP users.
Folders with names longer than 55 characters could become duplicated following an upgrade. Thunderbird 156 corrects this behavior.
Some newly downloaded POP messages also weren't receiving the normal new-message star after Thunderbird started.
That visual indicator should now work correctly.
Combined with the new custom OAuth support for POP3, Thunderbird 156 represents a meaningful update for users still relying on the older mail retrieval protocol.
SMTP Authentication Fixed for International Usernames
A particularly useful internationalization fix affects SMTP authentication.
Thunderbird could fail to authenticate when an SMTP username contained non-ASCII characters. Version 156 corrects the issue.
Email infrastructure increasingly needs to handle international character sets correctly, and assumptions that usernames will always contain only basic ASCII characters can cause frustrating account failures.
The fix should improve compatibility for users whose mail credentials contain characters outside the traditional English alphabet.
EWS Mailbox Synchronization Becomes More Reliable
Exchange Web Services also receives another important fix.
An unsupported EWS archive folder could previously prevent all mailbox folders from synchronizing.
Thunderbird 156 changes that behavior so one unsupported folder doesn't stop synchronization for the rest of the account.
This is especially important for enterprise Exchange accounts, where mailbox structures can be considerably more complicated than typical personal IMAP accounts.
A single unusual server-side folder should no longer make an otherwise functional mailbox appear broken.
Manual “Get Messages” Works Again
Thunderbird also corrects a frustrating mail retrieval problem.
In some circumstances, manually selecting Get Messages after starting Thunderbird didn't work until the user switched the application to offline mode and then back online.
Version 156 fixes the problem.
This is exactly the type of small but disruptive regression that can make an email client feel unreliable, particularly when users aren't aware that toggling offline mode provides a temporary workaround.
PDF Attachment Handling Gets Several Fixes
Attachments receive significant attention in Thunderbird 156.
Opening a PDF attachment inside a Thunderbird tab could result in an empty tab rather than displaying the document.
That issue has now been corrected.
Another bug could cause PDF attachments added from the compose window to be incorrectly identified as HTML content.
Thunderbird 156 fixes that MIME detection problem as well.
The update also corrects operations involving multiple attachments. After deleting one attachment, the Save All, Detach All, and Delete All commands could stop working correctly for the remaining attachments.
Detached Attachment Links Fixed
Thunderbird allows attachments to be detached from messages and stored separately on disk.
Version 156 corrects an issue where links to detached attachments could become truncated when the destination folder path contained an ampersand (&).
This could leave Thunderbird unable to correctly reference the detached file.
It's another relatively narrow bug, but an important one for users who regularly detach large attachments to reduce mailbox storage requirements.
S/MIME Warning Corrected
Thunderbird's S/MIME handling receives a correction as well.
A sent message signed using an expired S/MIME certificate could incorrectly display a warning suggesting that the certificate authority itself wasn't trusted.
Thunderbird 156 now handles this situation more accurately.
An expired certificate and an untrusted certificate authority are different problems, so distinguishing between them is important when users are diagnosing certificate or signature issues.
CalDAV Duplicate Invitations Fixed
Calendar users receive several noteworthy fixes.
One problem involved differences in capitalization between CalDAV email addresses. Thunderbird could interpret differently cased versions of the same address as separate identities, potentially resulting in duplicate calendar invitations.
Version 156 corrects that behavior.
Another issue could cause accepted CalDAV invitations to be stored in the wrong calendar.
That has also been fixed.
For users who rely on Thunderbird as both their email and calendar application, these synchronization corrections can be just as important as the mail-related improvements.
Folder Names Become More Resilient
Thunderbird 156 also changes how it deals with folders containing characters that aren't valid in filenames.
Under certain circumstances, losing Thunderbird's cache could cause those folders to appear using hashed names instead of their expected names.
The new release fixes the problem.
This is especially relevant because email folder names don't necessarily follow the same naming restrictions as files on the operating system's local filesystem.
Thunderbird has to translate between those two worlds without unexpectedly exposing internal representations to the user.
Message Thread Sorting Bug Fixed
Threaded message views receive another correction.
Deleting the only child message in a thread and then sorting the message list could cause the parent message to disappear from the view.
Thunderbird 156 fixes this behavior.
For users who organize conversations using Thunderbird's threaded display, predictable thread behavior is essential, especially in mailboxes containing large numbers of related messages.
Thundermail Add-On Updated
Thunderbird 156 also updates the built-in Thundermail add-on to version 2.0.11.
Thundermail is part of the broader Thunderbird ecosystem's work around its own email services and account infrastructure.
The update is listed as a change rather than one of the release's primary new features, but its inclusion demonstrates that Thunderbird's newer service components continue evolving alongside the desktop client.
Experimental Features Preference Renamed
Users who experiment with Thunderbird's less mature functionality should also be aware of a preference change.
The previous:
mail.offer_experimental_features
preference has been renamed to:
mail.experimental_features_settings.enabled
in Thunderbird 156.
This mostly matters to advanced users, testers, administrators, and developers who configure Thunderbird through about:config or automated deployment tools.
What Thunderbird 156 Means for Linux Users
Thunderbird 156 doesn't introduce a Linux-exclusive headline feature, but many of its improvements directly benefit Linux desktop users.
Better IMAP performance, expanded OAuth support, improved Exchange compatibility, corrected SMTP authentication, OpenPGP fixes, safer encrypted-message handling, PDF attachment corrections, and CalDAV reliability all apply to common Linux email workflows.
The application continues to support Linux systems running GTK+ 3.14 or later, meaning it remains compatible with a broad range of distributions.
Users should keep in mind that Thunderbird's upstream release date doesn't guarantee that version 156 will immediately appear in every Linux distribution's repositories.
Rolling distributions may package it quickly, while distributions following more conservative software policies may remain on an ESR branch or an older Thunderbird version and backport important security corrections.
Security Makes This an Important Upgrade
Although many of Thunderbird 156's visible changes are incremental, the accompanying security advisory makes the release more important than an ordinary collection of usability fixes.
Mozilla's advisory lists the security impact as high and confirms that Thunderbird 156 contains fixes for multiple vulnerabilities, including mail-header parsing and IMAP memory-safety issues.
For that reason, users running Thunderbird's monthly release channel should update when version 156 becomes available through their normal installation method.
Linux users whose distributions intentionally remain on Thunderbird ESR should follow their distribution's security updates rather than replacing packaged versions unnecessarily.
Conclusion
Thunderbird 156 is a security and reliability-focused release that strengthens several of the email client's most important underlying technologies. Released September 15, 2026, it expands custom OAuth support across IMAP and POP3, enables external browser authentication for Yandex, improves OpenPGP diagnostics, introduces new enterprise controls, and fixes a wide variety of mail, attachment, authentication, Exchange, and calendar problems.
Linux users benefit from faster handling of large IMAP folder collections, corrected SMTP authentication for non-ASCII usernames, improved EWS synchronization, better PDF attachment handling, and fixes affecting POP3 and CalDAV.
Most importantly, Thunderbird 156 includes a new set of security fixes, with Mozilla assigning the corresponding advisory a high impact rating.
It isn't a release defined by one enormous new feature. Instead, Thunderbird 156 concentrates on making everyday email, encryption, authentication, synchronization, and account management more dependable, which makes it a worthwhile update for Linux users running Thunderbird's monthly release channel.
