Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-52490: libtiff tiffcrop tool can let attackers run code

CVE-2026-52490 · published today
Summary

The libtiff image library, which many programs use to work with TIFF files, has a flaw in its tiffcrop utility that could allow a malicious user to run any program on the affected system. This could lead to loss of data or control of the server. Install the latest libtiff update or apply the vendor’s patch to close the gap.

What to do
  • Update tiff to version 4.7.0-3+deb13u3.aikido.10.
  • Update rootio-tiff to version 4.7.0-3+deb13u3.aikido.10.
  • Update debian tiff to version 4.7.2-1.
  • Update tiff to version 4.5.0-6+deb12u4.aikido.22.
  • Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.22.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:13 tiff < 4.7.0-3+deb13u3.aikido.10
Fix: upgrade to 4.7.0-3+deb13u3.aikido.10
Root:Debian:13 rootio-tiff < 4.7.0-3+deb13u3.aikido.10
Fix: upgrade to 4.7.0-3+deb13u3.aikido.10
Debian:11 debian tiff All versions
Debian:12 debian tiff All versions
Debian:13 debian tiff All versions
Debian:14 debian tiff < 4.7.2-1
Fix: upgrade to 4.7.2-1
Root:Debian:12 tiff < 4.5.0-6+deb12u4.aikido.22
Fix: upgrade to 4.5.0-6+deb12u4.aikido.22
Root:Debian:12 rootio-tiff < 4.5.0-6+deb12u4.aikido.22
Fix: upgrade to 4.5.0-6+deb12u4.aikido.22
Original advisory text
CVE-2026-52490 in tiff - Patched by Root
Root has patched CVE-2026-52490 in the tiff package for Root:Debian:13. Multiple fixed versions available.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen24 Aug 2026
Monitor software like this
Free during beta