ZeroHour
Wordfencepublished ()ingested Alex Thomas
Part of a story covered by 10 sources: “WordPress threat wave: active webshell campaign via WooCommerce Wholesale Lead Capture flaw CVE-2026-27540, plus Events Calendar, Tutor LMS, and libheif disclosures” — merged summary and timeline →

Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server

highVulnerabilityimportance 58
AI summary · glm-5.3-flash

Wordfence Argus disclosed a critical CVSS 9.8 flaw in libheif enabling protected-file disclosure and code execution on vulnerable server deployments.

Wordfence's Argus team discovered a critical CVSS 9.8 vulnerability in libheif, the open-source library many servers use to process HEIC images from iPhones. Researchers demonstrated protected-file disclosure and code execution on a specific WordPress deployment. Exploitation is described as target-specific, though the HEIF Heist research shows adapting image-parsing exploits to real systems is practical. No in-the-wild exploitation is reported and no CVE id is listed in the announcement.

  • Critical CVSS 9.8 vulnerability found in libheif, a widely used HEIC image library
  • Researchers demonstrated protected-file disclosure and code execution on a WordPress deployment
  • Exploitation is target-specific; no evidence of in-the-wild attacks
  • HEIF Heist work shows image exploits can be adapted to real-world systems
Full article

Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPress deployment. Exploitation is target-specific, but HEIF Heist shows that adapting image exploits to real systems is practical. The post Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server appeared first on Wordfence.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.