CVE-2026-61858: ImageMagick
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.
Affected products
- ImageMagick ImageMagick: before 6.9.13-51 (fixed in 6.9.13-51); from 7.0.0-0, before 7.1.2-26 (fixed in 7.1.2-26)
Published 2026-07-11. Last modified 2026-07-14.