CVE-2026-28687 | ImageMagick up to 6.9.13-40/7.1.2-15 MSL Decoder use after free (EUVD-2026-10377 / Nessus ID 303080)
A vulnerability was found in ImageMagick up to 6.9.13-40/7.1.2-15. It has been rated as critical. Affected by this issue is some unknown functionality of the component MSL Decoder. This manipulation causes use after free.
This vulnerability is tracked as CVE-2026-28687. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.