What is CVE-2026-62946?
In ImageMagick versions prior to 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This vulnerability can allow remote code execution, so users should immediately update to the patched versions.
Azərbaycanca: ImageMagick-in 6.9.13-52 və 7.1.2-27 öncəsi versiyalarında, 32-bit platformalarda çox böyük JNX fayllarının işlənməsi zamanı integer overflow nəticəsində heap buffer over-write zəifliyi mövcuddur. Bu zəiflikdən istifadə edərək uzaqdan kod icrası həyata keçirilə bilər, ona görə də istifadəçilər dərhal göstərilən versiyalara yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
How to protect against CVE-2026-62946?
By updating ImageMagick to version 6.9.13-52 or 7.1.2-27.
Can CVE-2026-62946 lead to remote code execution?
Yes, this vulnerability can allow remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.