CVE-2026-25971Disclosure(imagemagick / imagemagick)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch imagemagick imagemagick systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs, leading to a stack overflow. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
imagemagick

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-24: 2Mentions · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-12: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-12: 102-2403-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-03-121
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25971 ImageMagick Stack Overflow Vulnerability via Circular MSL... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25971 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A stack overflow vulnerability in ImageMagick via Circular MSL (CVE-2026-25971) is disclosed, with a link to details but no PoC, exploit, or patch information.

    0001164
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 ImageMagick, Uncontrolled Recursion, #CVE-2026-25971 (Critical) https://dailycve.com/imagemagick-uncontrolled-recursion-cve-2026-25971-critical/

    Post summary

    ImageMagick has a critical recursion-based denial‑of‑service flaw (CVE‑2026‑25971) that can be triggered by crafted image files; a patch has been issued to remedy the vulnerability.

    0000026
    167 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25971 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for cir… https://www.cve.org/CVERecord?id=CVE-2026-25971

    Post summary

    The text briefly references CVE-2026-25971 in ImageMagick, noting a failure to check for something before certain versions, but provides no further details.

    00000107
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more