CVE-2026-62439 is an Important-severity vulnerability in GIMP. Technical details, including the affected function and vulnerability class, are not available. The issue is fixed by GIMP commit 4427b9f31552060aafa5b03caee6ffdd6c257c8b and is addressed in GIMP 3.2.6.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Important-severity GIMP vulnerability fixed in GIMP 3.2.6. The provided CVSS vector indicates local attack access, low complexity, no required privileges, required user interaction, and potential high impact to confidentiality, integrity, and availability.
A critical, remotely exploitable vulnerability tracked as CVE-2026-62439, with a CVSS v3 vector indicating network access, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability. The provided detection metadata associates it with Ubuntu Linux LTS releases 16.04 through 26.04 and GIMP, but does not describe the underlying technical flaw.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.