Linuxsecurity openSUSE ImageMagick and 7zip Vulnerabilities Lead to Denial of Service Risks
Article Content
- •openSUSE has issued critical updates for vulnerabilities in ImageMagick and 7zip.
- •Multiple CVEs identified, including CVE-2026-45031 and CVE-2026-46520 for ImageMagick.
- •7zip vulnerabilities include CVE-2026-48092 and CVE-2026-48102, posing serious risks.
On June 30, 2026, openSUSE released advisories for critical vulnerabilities in ImageMagick and 7zip. ImageMagick has multiple CVEs including CVE-2026-45031 and CVE-2026-46520, leading to Denial of Service due to resource policy bypass and excessive resource use. 7zip also reported vulnerabilities such as CVE-2026-48092 and CVE-2026-48102, which allow for information disclosure and Denial of Service through crafted UDF images. These vulnerabilities affect openSUSE Leap 16.0 and could lead to significant disruptions if exploited. The vulnerabilities were published between June 5 and June 10, 2026, with patches available. Security professionals are urged to apply updates immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track OpenSUSE and CVE-2026-42326 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…