Imagemagick Vulnerabilities

Comprehensive security vulnerability database for Imagemagick products

Last updated: Mar 10, 2026
Total CVEs

9

Critical

0

With Exploits

8

Last 30 Days

15

Severity Distribution

Critical0
0%
High7
78%
Medium9
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-309365.5

An attacker can create a specially crafted image that, when processed by vulnerable versions of ImageMagick using the wavelet denoise feature, can lead to unintended memory changes, potentially allowing them to execute arbitrary code. This issue affects versions prior to 7.1.2-16 and 6.9.13-41, so updating to these versions or later is essential to mitigate the risk.

imagemagickimagemagick
Exploit Available
29 days agoMar 10, 2026
CVE-2026-309354.4

This vulnerability allows an attacker to cause an application using ImageMagick to read data from memory that it shouldn't, potentially exposing sensitive information. It occurs when processing specially crafted images with the bilateral blur feature, and it affects versions prior to 7.1.2-16.

imagemagickimagemagick
Exploit Available
29 days agoMar 10, 2026
CVE-2026-286924.8

This vulnerability allows an attacker to potentially read sensitive data from the memory of a system running vulnerable versions of ImageMagick when processing specially crafted image files. To exploit this, the attacker must be able to upload or manipulate images that the software will decode, which could lead to unauthorized access to information.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026
CVE-2026-286906.5

An attacker can exploit a flaw in the MNG image handling of ImageMagick to overwrite parts of the program's memory, potentially allowing them to run malicious code. This vulnerability affects versions prior to 7.1.2-16 and 6.9.13-41, and it requires the attacker to trick a user into processing a specially crafted MNG image.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026
CVE-2026-286896.3

This vulnerability allows an attacker to bypass security checks in ImageMagick, enabling them to read or write files they shouldn't have access to by tricking the software into using a different file than intended. To exploit this, the attacker needs to create a symbolic link (symlink) that swaps the intended file with a malicious one before the software opens it.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026
CVE-2026-286885.3

This vulnerability allows an attacker to potentially crash the ImageMagick software or execute arbitrary code by exploiting a flaw in how images are handled, specifically when a cloned image is improperly destroyed. It affects versions prior to 7.1.2-16 and 6.9.13-41, so users running older versions are at risk if they process untrusted image files.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026
CVE-2026-286875.3

An attacker can exploit a flaw in ImageMagick's MSL file processing to access and manipulate freed memory, potentially leading to crashes or arbitrary code execution if they can get a user to open a specially crafted MSL file. This vulnerability affects versions before 7.1.2-16 and 6.9.13-41, so updating to these versions or later is essential for protection.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026
CVE-2026-286866.8

This vulnerability allows an attacker to potentially execute malicious code on a system running vulnerable versions of ImageMagick by sending specially crafted PCL files, which can cause the software to crash or behave unexpectedly. To exploit this, the attacker needs access to a system where ImageMagick processes these files, making it important for users to update to the fixed versions to protect against this risk.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026
CVE-2026-284936.5

An attacker can exploit a vulnerability in ImageMagick to manipulate specially crafted images, potentially causing the software to crash or execute malicious code. This issue affects versions prior to 7.1.2-16, so updating to this version or later is essential to protect against it.

imagemagickimagemagick
Theoretical
29 days agoMar 10, 2026

About Imagemagick Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Imagemagick products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.