Skip to content
High-Risk CVE-2026-108693 Vulnerability in ImageMagick Disclosed

High-Risk CVE-2026-108693 Vulnerability in ImageMagick Disclosed

First seen 11 Oct 2026, 10:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC
  • •CVE-2026-108693 affects ImageMagick versions 7.1.2-33 and 6.9.13-58 on Windows.
  • •Attackers can exploit an uncontrolled path vulnerability to execute malicious code.
  • •A public proof-of-concept is available, but active exploitation has not been confirmed.

A high-risk vulnerability, CVE-2026-108693, has been identified in ImageMagick versions 7.1.2-33 and 6.9.13-58. This flaw allows attackers to exploit an uncontrolled path vulnerability in the Ghostscript delegate, enabling code execution through a malicious executable named gswin64c.exe. The vulnerability primarily affects Windows systems that utilize ImageMagick for processing PDF, PostScript, or EPS files. Attackers can plant a malicious executable in a writable directory, leading to potential unauthorized access to sensitive data. A proof-of-concept (PoC) has been made publicly available, but there is no confirmation of active exploitation in the wild at this time. Users are advised to review their conversion workflows and apply vendor patches as they become available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-11
CVE-2026-108693 published
ImageMagick disclosed a high-risk vulnerability allowing code execution via Ghostscript delegate handling.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-108693 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of ImageMagick are affected?
ImageMagick versions 7.1.2-33 and 6.9.13-58 are affected by CVE-2026-108693.
Is there a patch available?
The vendor is expected to release a patch; users should monitor for updates and apply them promptly.
How can I mitigate this vulnerability?
Review and restrict access to writable directories used by ImageMagick, and monitor for unexpected executions of gswin64c.exe.