Skip to content

CVE-2026-25646

CVE

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
February 10, 2026
Last Seen
April 10, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Two vulnerabilities have been identified in the libpng library affecting Fedora 42. The first, CVE-2026-25646, is a heap buffer overflow in the libpng12 package (version 1.2.57-25) and the second affects the libpng15 package (version 1.5.30-25). Both vulnerabilities allow for potential exploitation...

A critical vulnerability identified as CVE-2026-25646 has been found in libpng, affecting numerous operating systems and web browsers. This flaw, a heap buffer overflow in the png_set_quantize() function, could allow attackers to crash applications or execute arbitrary code. The vulnerability was pu...

The libpng package in Fedora has been updated to address CVE-2026-22695, a medium severity heap buffer over-read vulnerability. This affects users who manipulate PNG image files, necessitating an update to version 1.6.54 released on January 12, 2026.

Public Exploits

Checking GitHub for proof-of-concept code…