Linuxsecurity Critical ImageMagick Vulnerabilities Affect Multiple Ubuntu Versions
Article Content
- •ImageMagick vulnerabilities affect Ubuntu 14.04 LTS to 24.04 LTS.
- •CVE-2025-68950 and CVE-2026-28688 can lead to denial of service or arbitrary code execution.
- •Immediate system updates are recommended to mitigate these vulnerabilities.
Multiple vulnerabilities were discovered in ImageMagick, affecting Ubuntu versions 14.04 LTS through 24.04 LTS. The vulnerabilities include a stack overflow (CVE-2025-68950) and a use-after-free condition (CVE-2026-28688), both potentially leading to denial of service or arbitrary code execution. Additionally, CVE-2026-33900 involves an integer overflow that can cause out-of-bounds heap writes. These vulnerabilities were reported in July 2026, with the earliest CVE published in December 2025. Users are advised to update their systems to mitigate these risks. The vulnerabilities are particularly concerning due to their potential impact on a wide range of systems. The advisory emphasizes the importance of applying least privilege across Linux systems to reduce security risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ubuntu and CVE-2024-54661 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…