Vendor

ImageMagick

As of , 3 ImageMagick vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2016-3714.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2016-3714Improper Input ValidationImageMagick ImageMagickPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
2CVE-2016-3715Arbitrary File DeletionImageMagick ImageMagickPatch this weekEPSS 0.750.75
3CVE-2016-3718Server-Side Request Forgery (SSRF)ImageMagick ImageMagickPatch this weekEPSS 0.770.77

Added each year

0.511.522021: 2220212022: nonenone20222023: nonenone20232024: 1120242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20212
2022none
2023none
20241
2025none
2026none

Used in ransomware