CVE-2026-23876Patch(imagemagick / imagemagick)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch imagemagick imagemagick systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-14); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
imagemagick

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-10: 1Mentions · 2026-02-14: 2Mentions · 2026-02-23: 1Patch / Workaround · 2026-02-14: 2Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-14: 2Technical Details · 2026-02-23: 102-1002-1402-23
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-142
Patch2
2026-02-231
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ URGENT: Critical ImageMagick Security Patch for SUSE/openSUSE! A new update (SUSE-SU-2026:0503-1) is live, addressing three major vulnerabilities, including CVE-2026-23876—a critical remote code execution flaw (CVSS 9.8). Read more: 👉 https://tinyurl.com/3xn7nmdj #Security https://t.co/ABngFwNFzH

    Post summary

    SUSE released a patch (SUSE-SU-2026:0503-1) for the critical remote code execution CVE-2026-23876 in ImageMagick. No proof‑of‑concept, exploit code, or active exploitation is reported.

    0101047
    1.3K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A high-severity heap buffer overflow vulnerability in #ImageMagick could allow attackers to execute arbitrary code. #RCE #CVE-2026-23876 CVSS(3.1): 8.1. Read our advisory https://ccb.belgium.be/advisories/warning-heap-buffer-overflow-imagemagick-can-be-exploited-corrupt-memory-and-potentially and #Patch #Patch #Patch

    Post summary

    A high‑severity heap buffer overflow (CVE‑2026‑23876) in ImageMagick is disclosed with CVSS 8.1, and the advisory includes patch information.

    00001228
    7.2K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 URGENT: #SUSE #Linux Security Update 🚨 Patch critical #ImageMagick flaws NOW! CVE-2026-23876 allows potential remote code execution via malicious images. Check your SLES & openSUSE systems. Read more: 👉 https://tinyurl.com/3cbu7an9 #Security https://t.co/XwfCl0uMxL

    Post summary

    SUSE is urging users to patch ImageMagick immediately to mitigate a remote code execution vulnerability (CVE-2026-23876) that could be exploited via malicious images.

    0001064
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical vulnerability disclosure: CVE-2026-23876 in ImageMagick. Impacts the entire #Ubuntu LTS lineage . Read more: 👉 https://tinyurl.com/bdkk6j42 #Security https://t.co/CrSsp2wUEA

    Post summary

    The tweet announces the discovery of CVE-2026-23876, a critical ImageMagick flaw affecting Ubuntu LTS, but offers no further technical details or mitigation guidance.

    0000063
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more