Microsoft and security researchers disclosed two high-severity libpng vulnerabilities that can be triggered by processing crafted PNG files, exposing applications and services that rely on the library for image handling. CVE-2026-33416 is a use-after-free bug tied to pointer aliasing in png_set_tRNS and png_set_PLTE, affecting libpng through version 1.6.55; the flaw can cause heap corruption and may enable arbitrary code execution, particularly where protections such as ASLR or PIE are absent. Microsoft published guidance for CVE-2026-33416 through its Security Update Guide.
A second issue, CVE-2026-33636, affects ARM and AArch64 platforms in Neon-optimized palette expansion code introduced in version 1.6.36, creating an out-of-bounds read/write condition that can leak sensitive data, corrupt memory, and reliably crash processes. The vulnerabilities affect web applications, embedded devices, and server-side image processing pipelines that parse untrusted PNG content. Maintainers released patched versions 1.6.56 and 1.8.0; as a temporary mitigation for the ARM-specific flaw, organizations can rebuild libpng with hardware optimizations disabled.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Two high-severity libpng flaws, CVE-2026-33416 and CVE-2026-33636, were publicly disclosed as affecting crafted PNG parsing. Maintainers released libpng versions 1.6.56 and 1.8.0 to fix the issues, and a temporary workaround was noted for the ARM-specific flaw by disabling hardware optimizations during recompilation.
Microsoft's Security Update Guide listed CVE-2026-33416, a libpng use-after-free vulnerability caused by pointer aliasing in png_set_tRNS and png_set_PLTE.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.