Tenable
Multiple GIMP Vulnerabilities Allow Remote Code Execution
First seen 21 Feb 2026, 03:20 UTC
•

•84% similarity
•53.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Two vulnerabilities in GIMP have been identified, allowing remote attackers to execute arbitrary code. CVE-2026-2047 involves a heap-based buffer overflow in ICNS file parsing, while CVE-2026-2048 is related to improper validation in XWD file parsing, requiring user interaction for exploitation. Both vulnerabilities were published on February 20, 2026.
ThreatCluster AI
How this analysis works
Timeline
2026-02-20
CVE-2026-2047 published
2026-02-20
CVE-2026-2048 published
2026-02-21
Article published detailing vulnerabilities