SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-61861

LOW · CVSS 3.7 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-11 · Last synced 2026-08-10

CyberRota Analysis

AI-Generated

ImageMagick versions prior to 7.1.2-26 are susceptible to a use-after-free vulnerability in the FormatMagickCaption method, which occurs when memory allocation fails. This flaw can be exploited by attackers to create a dangling pointer that references freed memory, potentially leading to denial of service or arbitrary code execution. Organizations using ImageMagick should prioritize patching this vulnerability to mitigate associated risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61861
Severity
LOW
CVSS
3.7
EPSS
0.32%

Original NVD Description

ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution.

Related CVEs

Other vulnerabilities affecting the same vendor(s)