USN-8739-1: ImageMagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, CVE-2026-56373) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-56370) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56378) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379) It was discovered that ImageMagick incorrectly handled memory allocation in certain operations. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61465) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-61857) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly us
Details
Original advisory: https://ubuntu.com/security/notices/USN-8739-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-563660.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563680.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563710.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563730.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563700.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563780.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-563790.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-614650.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-618570.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-618630.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56366 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56368 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56371 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56373 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56370 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56378 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56379 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61465 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61857 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61863 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61864 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61865 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61870 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61866 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62946 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- low[UPDATE] [niedrig] ImageMagick: Mehrere Schwachstellen ermöglichen Denial of Servicecert-bund
- medium[UPDATE] [mittel] ImageMagick: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] ImageMagick: Schwachstelle ermöglicht Denial of Servicecert-bund
- medium[UPDATE] [mittel] ImageMagick: Mehrere Schwachstellen ermöglichen Denial of Servicecert-bund
- mediumCVE-2026-62946: ImageMagick is free and open-source software used for editing and manipulating digital images.…nvd
- mediumGHSA-h22j-f9xw-xjjm: ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processin…ghsa
- lowCVE-2026-61866: ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blo…nvd
- lowCVE-2026-61865: ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation:…nvd
- lowCVE-2026-61864: ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to th…nvd
- lowCVE-2026-61863: ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF enco…nvd
- lowCVE-2026-61870: ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memo…nvd
- lowCVE-2026-61857: ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing nul…nvd
More from Ubuntu Security Notices
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10
- unknownUSN-8744-1: Python vulnerabilities2026-09-10