Overview
What is CVE-2026-54122?
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.
Vulnerability intelligence
CVE-2026-54122 and is rated High severity with a CVSS score of 8.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.