Skip to content
Critical ImageMagick Vulnerabilities Affecting Multiple Ubuntu Versions

Critical ImageMagick Vulnerabilities Affecting Multiple Ubuntu Versions

First seen 25 Jun 2026, 18:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 26, 2026 at 17:55 UTC
  • •ImageMagick vulnerabilities affect Ubuntu 18.04, 20.04, 22.04, and 24.04 LTS.
  • •CVE-2026-28690 allows for arbitrary code execution via a stack buffer overflow.
  • •Users must update their systems to the latest ImageMagick versions to mitigate risks.

Multiple vulnerabilities in ImageMagick have been identified, affecting Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS. Key issues include a heap buffer over-read and a stack buffer overflow, which could lead to information disclosure and arbitrary code execution, respectively. The vulnerabilities are tracked under CVEs: CVE-2026-27798, CVE-2026-27799, and CVE-2026-28690. Additionally, CVE-2026-28691 and CVE-2026-28692 were also discovered, which could result in denial of service and further information disclosure. Users are advised to update their systems to mitigate these risks. The vulnerabilities were disclosed in a security advisory published on June 24, 2026, with a patch available for affected systems. The issues were confirmed by Ubuntu and Linuxsecurity reports.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-02-25
CVE-2026-27798 published
ImageMagick's heap buffer over-read vulnerability disclosed, affecting multiple Ubuntu versions.
Ubuntu
2026-02-25
CVE-2026-27799 published
Another heap buffer over-read vulnerability in ImageMagick confirmed, impacting the same Ubuntu versions.
Ubuntu
2026-03-09
CVE-2026-28690 published
A stack buffer overflow vulnerability in ImageMagick disclosed, allowing arbitrary code execution.
Ubuntu
2026-03-09
CVE-2026-28691 published
Denial of service vulnerability in ImageMagick identified, affecting certain JBIG images.
Ubuntu
2026-03-09
CVE-2026-28692 published
Heap buffer over-read vulnerability in ImageMagick confirmed, impacting MAT images.
Ubuntu
2026-03-09
CVE-2026-28693 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-24
Security advisory published
Ubuntu released an advisory detailing multiple vulnerabilities in ImageMagick and recommended updates.
Ubuntu
2026-06-25
Patch released
Ubuntu users are urged to update ImageMagick to the latest versions to address vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-27798 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed