CVE-2026-28493: ImageMagick

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.

Affected products

  • ImageMagick ImageMagick: before 7.1.2-16 (fixed in 7.1.2-16)

Published 2026-03-10. Last modified 2026-06-17.