dCERT issued two advisories on multiple vulnerabilities in ImageMagick, the widely used image processing suite, indicating ongoing security issues affecting the software. The advisories, 2026-0474 and 2026-0633, both identify ImageMagick as the impacted product but do not provide public synopses, suggesting organizations should review the vendor and downstream security guidance directly for affected versions and technical details.
Because ImageMagick is commonly embedded in web applications, content management systems, and backend media-processing pipelines, unpatched flaws can create risk across a broad range of environments. Security teams should inventory systems and applications that rely on ImageMagick, monitor for updated package releases and distribution-specific patches, and prioritize remediation to reduce exposure from potential image parsing and processing attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
dCERT published advisory 2026-1249 for ImageMagick vulnerabilities that can allow denial of service. The reference provides no additional technical details or remediation information.
dCERT issued advisory 2025-1671 for multiple vulnerabilities affecting ImageMagick. The reference provides no further technical details or remediation information.
dCERT issued advisory 2025-1764 for multiple vulnerabilities affecting ImageMagick. The reference provides no further technical details or remediation information.
dCERT published advisory 2026-1103 for multiple ImageMagick vulnerabilities that can allow denial of service. The reference provides no additional technical details or remediation information.
dCERT issued advisory 2026-1056 for multiple vulnerabilities affecting ImageMagick. The reference provides no further technical details or remediation information.
A new disclosure described two memory leak flaws in ImageMagick's ReadMETAImage function, including an unfreed StringInfo profile object and a leaked buff->blob allocation on jpeg_embed error handling. The issues can strand heap memory during META parsing, adding specific technical detail beyond earlier generic advisories.
dCERT published advisory 2026-0824 for multiple ImageMagick vulnerabilities that can allow denial of service. This represents a further advisory/update in the ongoing ImageMagick vulnerability disclosures.
dCERT later published advisory 2026-0633 covering multiple vulnerabilities in ImageMagick, indicating an additional or updated disclosure related to the software. The reference does not include specifics on the flaws or impact.
dCERT issued advisory 2026-0490 for multiple vulnerabilities affecting ImageMagick. The reference provides no further technical details or remediation information.
dCERT issued advisory 2026-0474 for multiple vulnerabilities affecting ImageMagick. The reference provides no further technical details or remediation information.
dCERT issued advisory 2026-0147 for multiple vulnerabilities affecting ImageMagick. The reference provides no further technical details or remediation information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcecvereports.com
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.