SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66011

LOW · CVSS 3.3 EPSS 0.09% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

ImageMagick versions prior to 7.1.2-27 are susceptible to a memory leak vulnerability in the command-line interface, which can be exploited by attackers through the repeated submission of invalid options. This can lead to memory exhaustion, potentially impacting system performance and availability. Organizations using ImageMagick should prioritize addressing this vulnerability to mitigate risks associated with resource depletion.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66011
Severity
LOW
CVSS
3.3
EPSS
0.09%

Original NVD Description

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

Related CVEs

Other vulnerabilities affecting the same vendor(s)