Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-32636
C# vulnerability analysis and mitigation

Overview

CVE-2026-32636 is a heap-buffer-overflow vulnerability in ImageMagick's NewXMLTree method that can result in an application crash due to an out-of-bounds write of a single zero byte. It affects ImageMagick versions prior to 7.1.2-17 (7.x branch) and prior to 6.9.13-42 (6.x branch), as well as the Magick.NET .NET wrapper prior to version 14.11.0. The vulnerability was reported by researcher "fumfel" and disclosed on March 16, 2026, with the GitHub Advisory Database entry published March 17, 2026. The CVSS v3.1 base score is 5.3 (Moderate) per the GitHub Security Advisory, though Feedly's aggregated data reflects a score of 7.5 (High) from some sources (GitHub Advisory, ImageMagick Advisory).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write): the NewXMLTree method writes a single zero byte past the end of an allocated buffer during XML tree construction, triggering a heap-buffer-overflow condition. The vulnerability is exploitable remotely over the network without authentication or user interaction, as ImageMagick is commonly invoked server-side to process user-supplied image or XML data. No public proof-of-concept exploit code has been identified, but the nature of the bug — a one-byte out-of-bounds null write — typically limits exploitability to denial of service (crash) rather than arbitrary code execution (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation causes ImageMagick to crash, resulting in a denial of service for any application or service that relies on ImageMagick for image or XML processing. There is no known confidentiality or integrity impact — the vulnerability does not expose sensitive data or allow unauthorized modification of data. In environments where ImageMagick processes untrusted input (e.g., web applications accepting image uploads), repeated exploitation could render the image processing pipeline unavailable (GitHub Advisory, ImageMagick Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-32636. The EPSS score is approximately 0.037% (0.000370), placing it in the 6th percentile for exploitation likelihood within 30 days, indicating a low probability of near-term weaponization (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

Mitigation and workarounds

Upgrade ImageMagick to version 7.1.2-17 or later (7.x branch) or 6.9.13-42 or later (6.x branch) to remediate the vulnerability. Users of the Magick.NET .NET wrapper should upgrade to version 14.11.0 or later. Red Hat Enterprise Linux 7 Extended Lifecycle Support users can apply the fix via errata RHSA-2026:17618. Ubuntu users should apply USN-8127-1, and openSUSE/SUSE users should apply the relevant security announcements. No configuration-based workarounds have been published; patching is the recommended remediation (ImageMagick Release, Magick.NET Release, Red Hat Bugzilla).

Community reactions

The vulnerability received routine coverage from Linux distribution security teams, with patches issued by Ubuntu (USN-8127-1), Red Hat (RHSA-2026:17618), openSUSE, Debian, and Amazon Linux 2. No notable researcher commentary or significant social media discussion beyond standard vulnerability tracking has been observed. The moderate severity rating and limited impact (DoS only) have kept community reaction subdued (Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

imagemagick: 8:6.9.11.60+dfsg-1.6+deb12u8

Fixed

sid

imagemagick: 8:7.1.2.18+dfsg1-1

Fixed

trixie

imagemagick: 8:7.1.1.43+dfsg1-1+deb13u8

Fixed

Ubuntu

Fixed

bionic (esm-infra)

imagemagick: 8:6.9.7.4+dfsg-16ubuntu6.15+esm11

Fixed

devel

imagemagick

Affected

focal (esm-apps)

imagemagick: 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9

Fixed

jammy

imagemagick

Affected

jammy (esm-apps)

imagemagick: 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9

Fixed

noble

imagemagick

Affected

noble (esm-apps)

imagemagick: 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8

Fixed

resolute

imagemagick

Affected

RHEL / CentOS

Unknown

Alpine

Fixed

edge

imagemagick: 7.1.2.17-r0

Fixed

v3.23

imagemagick: 7.1.2.17-r0

Fixed

SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69197HIGH8.7
  • C# logoC#
  • Umbraco.Cms
NoYesSep 17, 2026
CVE-2026-81516HIGH7.5
  • C# logoC#
  • Steeltoe.Discovery.Consul
NoYesSep 17, 2026
CVE-2026-81515HIGH7.5
  • C# logoC#
  • Steeltoe.Discovery.Eureka
NoYesSep 17, 2026
CVE-2026-81868MEDIUM6.5
  • C# logoC#
  • Steeltoe.Security.Authorization.Certificate
NoYesSep 17, 2026
CVE-2026-75523MEDIUM5.9
  • C# logoC#
  • Steeltoe.Management.Endpoint
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management