CVE-2026-46522Disclosure(imagemagick / imagemagick)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch imagemagick imagemagick systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-835

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • imagemagick

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
imagemagick

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-17: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-17: 1Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-19: 105-1705-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - ImageMagick MIFF Decoder Denial of Service (CVE-2026-46522) A high-severity uncontrolled resource consumption vulnerability in ImageMagick allows remote attackers to cause a Denial of Service (DoS). Due to a missing boundary check in the MIFF (Magick Image File Format) decoder, parsing a maliciously crafted image file triggers an infinite loop, rapidly resulting in total CPU exhaustion and system instability. 👉 Affected: Magick. NET NuGet Packages (Multiple variations) < 14.13.1 | Upgrade to 14.13.1

    Post summary

    The advisory announces a high‑severity Denial of Service vulnerability in ImageMagick’s MIFF decoder, details the technical cause, and recommends upgrading to version 14.13.1 to remediate the issue.

    00020161
    255 followersView on X
  • Bl4cksku11@bl4cksku111
    Disclosure

    CVE-2026-46522 in @ImageMagick https://bl4cksku11.com/blog/p/imagemagick-miff-bzip-dos/ Patched: 7.1.2-23 / 6.9.13-48. A 224-byte MIFF that pins ImageMagick at 100% CPU - bl4cksku11 #cve #infosec #vulnresearch

    Post summary

    The post announces CVE‑2026‑46522 affecting ImageMagick, gives a PoC via a blog link, specifies a 224‑byte MIFF that triggers a CPU‑bound DoS, and lists the patched versions.

    0000098
    81 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appimagemagickimagemagick---

Explore more