PatchSiren cyber security CVE debrief
CVE-2026-86425 ImageMagick CVE debrief
CVE-2026-86425 is a heap-use-after-free vulnerability in ImageMagick's PerlMagick Layer method. An attacker can trigger a denial of service by supplying a crafted list of images. This vulnerability affects ImageMagick versions before 7.1.2-30 and 6.9.x before 6.9.13-55. Defenders should assess exposure and prioritize patching to prevent potential denial of service attacks. The vulnerability has a medium severity and can be exploited through crafted image inputs, potentially leading to memory corruption and crashes.
- Vendor
- ImageMagick
- Product
- Unknown
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for ImageMagick installations, particularly those using PerlMagick, should assess exposure and prioritize patching to prevent potential denial of service attacks.
Why it matters
CVE-2026-86425 is a medium-severity vulnerability in ImageMagick's PerlMagick Layer method. Defenders should prioritize verifying ImageMagick versions and applying patches to prevent potential denial of service attacks.
- Denial of service attacks via crafted image inputs
- Potential for memory corruption and crashes
Technical summary
The Layer method of PerlMagick in ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability. An attacker can trigger memory access after deallocation by supplying a crafted list of images, resulting in a crash. This vulnerability has a CVSS score of 4.8 and a medium severity. Defenders should prioritize verifying ImageMagick versions and applying patches to prevent potential denial of service attacks. The vulnerability can be exploited through crafted image inputs, potentially leading to memory corruption and crashes.
Defensive priority
Defenders should prioritize verifying ImageMagick versions and applying patches to prevent potential denial of service attacks.
Recommended defensive actions
- Verify ImageMagick versions and apply patches
- Monitor for crafted image inputs
- Implement memory access controls
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its medium severity and potential for denial of service attacks. Additional information on affected versions and remediation is needed. The vulnerability is in the PerlMagick Layer method, and defenders should verify ImageMagick versions and apply patches. The CVE record was published on 2026-09-07T13:20:41.543Z and has not been modified since then. No additional information on exploitation or in-the-wild attacks is available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86425 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86425
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86425 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86425
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-heap-use-after-free-via-layer
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.