AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-59087

HIGH · CVSS 7.8 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the GIMP image manipulation program's Seattle Filmworks file loader allows remote attackers to exploit a heap overflow by convincing users to open a specially crafted file. This can lead to memory corruption, potentially enabling arbitrary code execution or causing a denial of service. Organizations using GIMP, especially those handling untrusted image files, should prioritize addressing this issue to mitigate the associated risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59087
Severity
HIGH
CVSS
7.8
EPSS
0.23%

Original NVD Description

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.