Multiple ImageMagick vulnerabilities were disclosed affecting common image-processing deployments (web apps, CMS integrations, and automated pipelines). CVE-2026-25794 is a heap-based buffer overflow triggered when writing UHDR images: WriteUHDRImage (coders/uhdr.c) uses 32-bit int arithmetic to compute pixel buffer size, allowing a signed integer overflow on large dimensions that leads to an undersized heap allocation and out-of-bounds write; ImageMagick 7.1.2-15 includes a patch. Separately, Belgium’s CCB warned that CVE-2026-23876 is a high-severity heap buffer overflow in the XBM decoder (ReadXBMImage) that can be triggered by a crafted image and may enable memory corruption and potential code execution; the advisory notes a public PoC and urges immediate patching.
A second ImageMagick issue, CVE-2026-25965, allows a policy bypass via path traversal because the path security policy is applied to the raw filename string before filesystem normalization; attackers can use traversal to read sensitive files (local file disclosure) even when policy-secure.xml is in place. Fixes were reported in ImageMagick 7.1.2-15 and 6.9.13-40, and guidance indicates policy hardening may be required to ensure write operations are also blocked. A separate disclosure for Traccar stored XSS via malicious SVG upload is unrelated to the ImageMagick issues and should be tracked independently.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Public advisories described CVE-2026-25794, a heap buffer overflow in WriteUHDRImage, and CVE-2026-25965, a path traversal-based policy bypass that could expose restricted files. Both disclosures identified affected versions and available fixes.
The CVE-2026-25965 advisory was received by security-advisories@github.com, documenting the ImageMagick path traversal issue and its impact on policy enforcement. This marks the formal intake of the vulnerability report referenced by the CVE entry.
ImageMagick fixed CVE-2026-25794, a heap buffer overflow in WriteUHDRImage caused by signed integer overflow when handling large UHDR image dimensions. The flaw could crash the process and potentially enable out-of-bounds heap writes with security impact.
ImageMagick addressed a path traversal flaw that could bypass policy-secure.xml protections and allow local file disclosure by normalizing or otherwise blocking restricted file access. The fix was included in versions 7.1.2-15 and 6.9.13-40, with notes that additional default policy hardening for write protections would follow.
Belgium's Centre for Cybersecurity issued a warning that the ImageMagick heap buffer overflow could be exploited to corrupt memory and potentially compromise affected systems. The advisory noted that proof-of-concept exploit code was available and urged immediate patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceccb.belgium.be
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.