CVE-2026-52490

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

Published 2026-08-24. Last modified 2026-09-09.