PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86422 ImageMagick CVE debrief

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows. This allows attackers to bypass read or write restrictions by exploiting symlink race conditions. The vulnerability affects ImageMagick installations on Windows systems, where attackers can swap symlinks between policy validation and file access to read or write policy-denied files. Defenders should assess exposure and prioritize updates to version 7.1.2-30 or later. The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 1 and severity of LOW.

Vendor
ImageMagick
Product
Unknown
CVSS
LOW 1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders responsible for ImageMagick installations on Windows systems should assess exposure and prioritize updates to version 7.1.2-30 or later. This includes verifying and updating ImageMagick installations, assessing exposure on Windows systems, and monitoring for potential attacks. Security teams and vulnerability management teams should also review the vulnerability and plan vendor-supported updates or mitigations through normal change control where

Why it matters

CVE-2026-86422 is a time-of-check-time-of-use vulnerability in ImageMagick on Windows that allows attackers to bypass read or write restrictions. Defenders should prioritize verifying and updating ImageMagick installations, assessing exposure on Windows systems, and monitoring for potential attacks.

  • Verify and update ImageMagick installations to prevent potential symlink race condition attacks
  • Assess exposure on Windows systems and prioritize updates for vulnerable installations
  • Monitor for potential attacks exploiting this vulnerability

Technical summary

The vulnerability exists in ImageMagick before version 7.1.2-30 on Windows, allowing attackers to bypass read or write restrictions by exploiting symlink race conditions during path policy enforcement. This occurs when attackers swap symlinks between policy validation and file access to read or write policy-denied files. The vulnerability affects ImageMagick installations on Windows systems. Defenders should prioritize verifying and updating ImageMagick installations to version 7.1.2-30 or later, and assess exposure on Windows systems.

Defensive priority

Defenders should prioritize verifying and updating ImageMagick installations to version 7.1.2-30 or later, and assess exposure on Windows systems.

Recommended defensive actions

  • Verify ImageMagick installations are up-to-date on Windows systems
  • Assess exposure and prioritize updates for vulnerable installations
  • Monitor for potential symlink race condition attacks on Windows
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 1 and severity of LOW. The vulnerability exists in ImageMagick before version 7.1.2-30 on Windows, allowing attackers to bypass read or write restrictions by exploiting symlink race conditions during path policy enforcement. Defenders should verify and update ImageMagick installations to version 7.1.2-30 or later, and assess exposure on Windows systems. The source detail is limited, and defenders should prioritize verifying and The

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86422 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86422

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86422 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86422

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.