ImageMagick Alert (CVE-2026-23876): “XBM” Image Uploads Trigger Massive Heap Overflow
ID: be905b40-8e58-5dc4-b5a3-2bf1114ea462
STIX ID: report--be905b40-8e58-5dc4-b5a3-2bf1114ea462
Feed Name: securityonline.info
Threat Score
**ImageMagick CVE-2026-23876:** A high-severity integer-truncation flaw in the XBM decoder can cause a massive heap buffer overflow when processing crafted XBM images; with a CVSS of 8.1, the vulnerability allows remote attackers to upload images that overwrite heap memory and potentially achieve code execution. Affected versions are ImageMagick prior to 7.1.2-13 and 6.9.13-38; maintainers released patches and administrators should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
