logo

ImageMagick Alert (CVE-2026-23876): “XBM” Image Uploads Trigger Massive Heap Overflow

ID: be905b40-8e58-5dc4-b5a3-2bf1114ea462

STIX ID: report--be905b40-8e58-5dc4-b5a3-2bf1114ea462

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

**ImageMagick CVE-2026-23876:** A high-severity integer-truncation flaw in the XBM decoder can cause a massive heap buffer overflow when processing crafted XBM images; with a CVSS of 8.1, the vulnerability allows remote attackers to upload images that overwrite heap memory and potentially achieve code execution. Affected versions are ImageMagick prior to 7.1.2-13 and 6.9.13-38; maintainers released patches and administrators should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.