German government advisories warned of security flaws in two widely used image-processing applications, with GIMP affected by a vulnerability that could allow code execution and ImageMagick affected by a separate flaw that could enable an unspecified attack. The notices identify both products as requiring security review because they are commonly used to open, convert, and manipulate untrusted image files in desktop and server-side workflows.
The GIMP issue presents the more severe risk because successful exploitation could let an attacker run code on a target system, while the ImageMagick issue may expose systems that rely on automated image handling to further compromise depending on deployment context. Organizations using either tool in user workstations, content pipelines, or backend processing environments should verify affected versions, apply vendor fixes or distribution updates, and restrict processing of untrusted files until remediation is complete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
dCERT published Advisory 2026-1117 for GIMP, indicating multiple vulnerabilities. The reference provides no additional technical details or remediation information.
dCERT published Advisory 2025-2669 for GIMP, warning that multiple vulnerabilities could allow code execution. The reference provides no additional technical details or remediation information.
dCERT published Advisory 2026-0784 for GIMP, warning that multiple vulnerabilities could allow code execution. The reference provides no additional technical details or remediation information.
dCERT published Advisory 2026-0702 for ImageMagick, stating that the vulnerability could allow an unspecified attack. No further technical details are included in the reference.
dCERT published Advisory 2026-0276 for GIMP, stating that the vulnerability could allow code execution. No additional technical details or remediation information are provided in the reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.