CVE-2026-25968Disclosure(imagemagick / imagemagick)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-24); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
imagemagick

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-12: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-12: 102-2402-2702-2803-0103-12
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure2
2026-02-271
General1
2026-02-281
General1
2026-03-011
Disclosure1
2026-03-121
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25968 Stack Buffer Overflow in ImageMagick Prior to 7.1.2-15 and 6.9.13-40 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25968

    Post summary

    A stack buffer overflow vulnerability (CVE-2026-25968) affecting ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 has been disclosed, with no mention of PoC, exploit, or patch.

    0001145
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 ImageMagick, Stack Buffer Overflow, #CVE-2026-25968 (Critical) https://dailycve.com/imagemagick-stack-buffer-overflow-cve-2026-25968-critical/

    Post summary

    A new critical stack buffer overflow vulnerability (CVE‑2026‑25968) in ImageMagick has been disclosed.

    0000022
    167 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25968 (CVSS:7.4, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1..https://nvd.nist.gov/vuln/detail/CVE-2026-25968 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-25968, a high‑severity vulnerability in ImageMagick affecting versions prior to 7.1.2-1, with CVSS 7.4, but provides no PoC, exploit, or patch details.

    0000024
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25968 (CVSS:7.4, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1..https://nvd.nist.gov/vuln/detail/CVE-2026-25968 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post merely cites CVE‑2026‑25968 with its CVSS rating and notes the affected software, but it provides no further technical, exploitation, or mitigation information.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-25968 (CVSS:7.4, HIGH) is Analyzed. ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1..https://nvd.nist.gov/vuln/detail/CVE-2026-25968 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-25968 with CVSS and affected ImageMagick versions, but provides no PoC, exploit code, patch, or active‑exploitation details.

    0000027
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25968 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occur… https://www.cve.org/CVERecord?id=CVE-2026-25968

    Post summary

    The post announces a stack buffer overflow vulnerability in ImageMagick affecting versions prior to 7.1.2-15 and 6.9.13-40, with no PoC, exploit code, or patch details provided.

    00000111
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more