VulnSea

AcademySoftwareFoundation has 17 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 12. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-125 (8) and CWE-787 (8). Most affected products: OpenImageIO (12), openexr (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
15 prev 1

Products

  • OpenImageIO 12
  • openexr 5
Follow AcademySoftwareFoundation:RSS feedSave a search →Embed badge ↗
17
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

AcademySoftwareFoundation vulnerabilities

CVEs affecting AcademySoftwareFoundation, newest first. Open any entry for full detail, references, and exploit status.

17 CVEsRSS

CVE-2026-67549High· 7.6
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so cal…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.26%via NVD
CVE-2026-65970Medium· 5.3PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFIn…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.37%via NVD
CVE-2026-65969Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is proce…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.13%via NVD
CVE-2026-63638High· 8.3
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted cineon image can declare unsupported component bi…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.24%via NVD
CVE-2026-63635Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal va…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.15%via NVD
CVE-2026-63422High· 7.8
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple o…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.14%via NVD
CVE-2026-63420Medium· 5.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer sto…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.13%via NVD
CVE-2026-63419High· 7.8PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public im…

MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.21%via NVD
CVE-2026-59956Medium· 6.1PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffi…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-59181Medium· 6.1PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value g…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-59156Medium· 6.5
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte head…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.33%via NVD
CVE-2026-50291Medium· 5.5
4d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application l…

SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.14%via NVD
CVE-2026-59984Medium· 5.5PoC
3w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

TwilightAcademySoftwareFoundation · openexrEPSS 0.18%via NVD
CVE-2026-59985Medium· 5.5PoC
3w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32…

TwilightAcademySoftwareFoundation · openexrEPSS 0.18%via NVD
CVE-2026-61555Medium· 5.5
3w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. Th…

SunlitAcademySoftwareFoundation · openexrEPSS 0.17%via NVD
CVE-2026-34588High· 8.6
5mo ago

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working w…

TwilightAcademySoftwareFoundation · openexrEPSS 0.48%via CVEORG
CVE-2026-27622High· 8.4
6mo ago

OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…

TwilightAcademySoftwareFoundation · openexrEPSS 0.20%via CVEORG
AcademySoftwareFoundation vulnerabilities (CVEs) · VulnSea