CVE-2026-28693
published 2026-03-10CVE-2026-28693: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in…
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.33%
25.7th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.2.16+dfsg1-1 (forky) | imagemagick 8:7.1.2.16+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 6.9.13-41 | 6.9.13-41 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u7 | 8:7.1.1.43+dfsg1-1+deb13u7 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.16+dfsg1-1 | 8:7.1.2.16+dfsg1-1 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-16 | 7.1.2-16 |
| ubuntu | imagemagick | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2026-06-24·CVSS 7.1
CVE-2026-28691 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operator. An attacker could possibly use
this issue to trigger a heap buffer over-read, resulting in information
disclosure. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-27798)
It was discovered that ImageMagick incorrectly handled certain DJVU
images. An attacker could possibly use this issue to trigger a heap
buffer over-read, resulting in information disclosure. (CVE-2026-27799)
It was discovered that ImageMagick incorrectly handled certain MNG
images. An attacker could possibly use this issue to trigger a stack
buffer overfl
Red Hat
ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
vendor_redhat·2026-03-09·CVSS 8.1
CVE-2026-28693 [HIGH] CWE-190 ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. An integer overflow vulnerability in the DIB (Device Independent Bitmap) coder component can be exploited by a remote attacker. By processing a specially crafted image file, this flaw may lead to an out-of-bounds read or write, potentially resulting in arbitrary code execution, privilege escalation, information disclosure,
Debian
CVE-2026-28693: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2026·CVSS 8.1
CVE-2026-28693 [HIGH] CVE-2026-28693: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7.1.2.16+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.16+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u7)
VulDB
ImageMagick up to 6.9.13-40/7.1.2-15 DIB Coder out-of-bounds write (EUVD-2026-10389 / Nessus ID 303080)
vuldb·2026-04-22·CVSS 8.1
CVE-2026-28693 [HIGH] ImageMagick up to 6.9.13-40/7.1.2-15 DIB Coder out-of-bounds write (EUVD-2026-10389 / Nessus ID 303080)
A vulnerability, which was classified as critical, was found in ImageMagick up to 6.9.13-40/7.1.2-15. This affects an unknown part of the component DIB Coder. The manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2026-28693. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
OSV
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
osv·2026-03-12
CVE-2026-28693 [HIGH] ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
An integer overflow in DIB coder can result in out of bounds read or write
GHSA
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
ghsa·2026-03-12
CVE-2026-28693 [HIGH] CWE-125 ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
An integer overflow in DIB coder can result in out of bounds read or write
OSV
CVE-2026-28693: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2026-03-10·CVSS 8.1
CVE-2026-28693 [HIGH] CVE-2026-28693: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28693 ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
bugzilla·2026-03-09·CVSS 8.1
CVE-2026-28693 [HIGH] CVE-2026-28693 ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
CVE-2026-28693 ImageMagick: ImageMagick: Out-of-bounds read or write due to integer overflow in DIB coder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2026:6713 https://access.redhat.com/errata/RHSA-2026:6713
Wiz
CVE-2026-28693 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-28693 [HIGH] CVE-2026-28693 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28693 :
C# vulnerability analysis and mitigation
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Source : NVD
## 8.1
Score
Published March 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
C#
ImageMagick
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
perl-PerlMagick
ImageMagick-debuginfo
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76https://access.redhat.com/errata/RHSA-2026:6713https://access.redhat.com/security/cve/CVE-2026-28693https://bugzilla.redhat.com/show_bug.cgi?id=2445888https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json
2026-03-10
Published